Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2 712

Количество 2 712

debian логотип

CVE-2012-5479

больше 13 лет назад

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2012-5473

больше 13 лет назад

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-5473

больше 13 лет назад

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-5473

больше 13 лет назад

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-5472

больше 13 лет назад

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2012-5472

больше 13 лет назад

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2012-5472

больше 13 лет назад

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 a ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2012-5471

больше 13 лет назад

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-5471

больше 13 лет назад

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2012-5471

больше 13 лет назад

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4408

почти 14 лет назад

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2012-4408

почти 14 лет назад

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2012-4408

почти 14 лет назад

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ...

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2012-4407

почти 14 лет назад

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-4407

почти 14 лет назад

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-4407

почти 14 лет назад

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-4403

почти 14 лет назад

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-4403

почти 14 лет назад

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-4403

почти 14 лет назад

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly con ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-4402

почти 14 лет назад

webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.

CVSS2: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2012-5479

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, ...

CVSS2: 6.5
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5473

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.

CVSS2: 4
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5473

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.

CVSS2: 4
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-5473

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x befor ...

CVSS2: 4
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5472

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

CVSS2: 4
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5472

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.

CVSS2: 4
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-5472

lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 a ...

CVSS2: 4
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-5471

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

CVSS2: 6.5
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-5471

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.

CVSS2: 6.5
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-5471

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x ...

CVSS2: 6.5
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2012-4408

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.

CVSS2: 5.5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4408

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.

CVSS2: 5.5
1%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-4408

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ...

CVSS2: 5.5
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4407

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

CVSS2: 5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4407

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.

CVSS2: 5
1%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-4407

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and ...

CVSS2: 5
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4403

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

CVSS2: 5
1%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-4403

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.

CVSS2: 5
1%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-4403

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly con ...

CVSS2: 5
1%
Низкий
почти 14 лет назад
ubuntu логотип
CVE-2012-4402

webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.

CVSS2: 4.9
1%
Низкий
почти 14 лет назад

Уязвимостей на страницу