Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 535

Количество 2 535

debian логотип

CVE-2012-6101

больше 12 лет назад

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2 ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2012-6100

больше 12 лет назад

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-6100

больше 12 лет назад

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-6100

больше 12 лет назад

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2. ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-6099

больше 12 лет назад

The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-6099

больше 12 лет назад

The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-6099

больше 12 лет назад

The moodle1 backup converter in backup/converter/moodle1/lib.php in Mo ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-6098

больше 12 лет назад

grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-6098

больше 12 лет назад

grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-6098

больше 12 лет назад

grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-6087

почти 12 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2012-6087

почти 12 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2012-6087

почти 12 лет назад

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11 ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2012-5481

больше 12 лет назад

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-5481

больше 12 лет назад

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-5481

больше 12 лет назад

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-5480

больше 12 лет назад

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-5480

больше 12 лет назад

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2012-5480

больше 12 лет назад

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2012-5479

больше 12 лет назад

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

CVSS2: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2012-6101

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2 ...

CVSS2: 5.8
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-6100

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.

CVSS2: 4
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-6100

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.

CVSS2: 4
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-6100

report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2. ...

CVSS2: 4
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-6099

The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.

CVSS2: 4
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-6099

The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.

CVSS2: 4
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-6099

The moodle1 backup converter in backup/converter/moodle1/lib.php in Mo ...

CVSS2: 4
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-6098

grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.

CVSS2: 4
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-6098

grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.

CVSS2: 4
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-6098

grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x ...

CVSS2: 4
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
0%
Низкий
почти 12 лет назад
nvd логотип
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

CVSS2: 5.8
0%
Низкий
почти 12 лет назад
debian логотип
CVE-2012-6087

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11 ...

CVSS2: 5.8
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2012-5481

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

CVSS2: 4
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-5481

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.

CVSS2: 4
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-5481

Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass ...

CVSS2: 4
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-5480

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

CVSS2: 6.4
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2012-5480

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.

CVSS2: 6.4
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2012-5480

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ...

CVSS2: 6.4
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2012-5479

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.

CVSS2: 6.5
1%
Низкий
больше 12 лет назад

Уязвимостей на страницу