Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 643

Количество 2 643

debian логотип

CVE-2011-4306

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in course/editsection.html in ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4305

больше 13 лет назад

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-4305

больше 13 лет назад

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-4305

больше 13 лет назад

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authen ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-4304

больше 13 лет назад

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-4304

больше 13 лет назад

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-4304

больше 13 лет назад

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2 ...

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-4303

больше 13 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-4303

больше 13 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4303

больше 13 лет назад

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4302

больше 13 лет назад

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-4302

больше 13 лет назад

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4302

больше 13 лет назад

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x be ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4301

больше 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4301

больше 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4301

больше 13 лет назад

The MoodleQuickForm class in the Forms Library in lib/formslib.php in ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4300

больше 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-4300

больше 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-4300

больше 13 лет назад

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x befo ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-4299

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2011-4306

Cross-site scripting (XSS) vulnerability in course/editsection.html in ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4305

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

CVSS2: 4
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4305

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4305

message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authen ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4304

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

CVSS2: 4
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4304

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.

CVSS2: 4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4304

The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2 ...

CVSS2: 4
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4303

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4303

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4303

lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4302

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4302

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4302

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x be ...

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4301

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

CVSS2: 5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4301

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.

CVSS2: 5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4301

The MoodleQuickForm class in the Forms Library in lib/formslib.php in ...

CVSS2: 5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file.

CVSS2: 5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x befo ...

CVSS2: 5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4299

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу