Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

debian логотип

CVE-2008-5432

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 b ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-5153

больше 16 лет назад

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

CVSS2: 6.9
EPSS: Низкий
redhat логотип

CVE-2008-5153

почти 17 лет назад

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

EPSS: Низкий
nvd логотип

CVE-2008-5153

больше 16 лет назад

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2008-5153

больше 16 лет назад

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite ...

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2008-3327

почти 17 лет назад

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3327

почти 17 лет назад

Moodle 1.6.5, when display_errors is enabled, allows remote attackers ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3326

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-3326

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2008-3326

почти 17 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1. ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2008-3325

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2008-3325

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2008-3325

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before ...

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2008-0123

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-0123

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-0123

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3555

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3555

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-3555

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-1647

больше 18 лет назад

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

CVSS2: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2008-5432

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 b ...

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

CVSS2: 6.9
0%
Низкий
больше 16 лет назад
redhat логотип
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

CVSS2: 6.9
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite ...

CVSS2: 6.9
0%
Низкий
больше 16 лет назад
nvd логотип
CVE-2008-3327

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3327

Moodle 1.6.5, when display_errors is enabled, allows remote attackers ...

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3326

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3326

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3326

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1. ...

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
0%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
0%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before ...

CVSS2: 6
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-0123

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-0123

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-0123

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8 ...

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2007-3555

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
5%
Низкий
почти 18 лет назад
nvd логотип
CVE-2007-3555

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.

CVSS2: 4.3
5%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-3555

Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 ...

CVSS2: 4.3
5%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-1647

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

CVSS2: 7.8
3%
Низкий
больше 18 лет назад

Уязвимостей на страницу