Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2012-2361

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-2361

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-2360

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2012-2360

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.

CVSS2: 3.5
EPSS: Низкий
debian логотип

CVE-2012-2360

почти 13 лет назад

Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Mood ...

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2012-2359

почти 13 лет назад

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-2359

почти 13 лет назад

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2012-2359

почти 13 лет назад

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2. ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2012-2358

почти 13 лет назад

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-2358

почти 13 лет назад

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2012-2358

почти 13 лет назад

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 ...

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-2357

почти 13 лет назад

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-2357

почти 13 лет назад

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-2357

почти 13 лет назад

The Multi-Authentication feature in the Central Authentication Service ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-2356

почти 13 лет назад

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-2356

почти 13 лет назад

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2356

почти 13 лет назад

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-2355

почти 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-2355

почти 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-2355

почти 13 лет назад

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-2361

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2361

Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php ...

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-2360

Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-2360

Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2360

Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Mood ...

CVSS2: 3.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-2359

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.

CVSS2: 6.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-2359

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.

CVSS2: 6.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2359

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2. ...

CVSS2: 6.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-2358

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-2358

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2358

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 ...

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-2357

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-2357

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

CVSS2: 5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2357

The Multi-Authentication feature in the Central Authentication Service ...

CVSS2: 5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-2356

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.

CVSS2: 4
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-2356

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.

CVSS2: 4
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2356

The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x ...

CVSS2: 4
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-2355

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-2355

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

CVSS2: 4
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-2355

Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authent ...

CVSS2: 4
0%
Низкий
почти 13 лет назад

Уязвимостей на страницу