Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2012-0800

почти 13 лет назад

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2012-0800

почти 13 лет назад

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2. ...

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2012-0799

почти 13 лет назад

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-0799

почти 13 лет назад

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-0799

почти 13 лет назад

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous fr ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2012-0798

почти 13 лет назад

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-0798

почти 13 лет назад

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2012-0798

почти 13 лет назад

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2. ...

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0797

почти 13 лет назад

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-0797

почти 13 лет назад

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2012-0797

почти 13 лет назад

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x befo ...

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0796

почти 13 лет назад

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-0796

почти 13 лет назад

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-0796

почти 13 лет назад

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-0795

почти 13 лет назад

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-0795

почти 13 лет назад

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2012-0795

почти 13 лет назад

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, an ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0794

почти 13 лет назад

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-0794

почти 13 лет назад

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-0794

почти 13 лет назад

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1. ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-0800

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by accessing a create-groups page with Safari on an iPad device.

CVSS2: 2.1
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0800

The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2. ...

CVSS2: 2.1
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-0799

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0799

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0799

Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous fr ...

CVSS2: 4.3
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-0798

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0798

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0798

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2. ...

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-0797

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0797

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0797

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x befo ...

CVSS2: 5.5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-0796

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.

CVSS2: 4
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0796

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.

CVSS2: 4
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0796

class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x ...

CVSS2: 4
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-0795

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

CVSS2: 6.5
1%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0795

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.

CVSS2: 6.5
1%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0795

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, an ...

CVSS2: 6.5
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-0794

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

CVSS2: 5
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-0794

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.

CVSS2: 5
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2012-0794

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1. ...

CVSS2: 5
0%
Низкий
почти 13 лет назад

Уязвимостей на страницу