Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 643

Количество 2 643

nvd логотип

CVE-2011-4299

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-4299

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Mo ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2011-4298

больше 13 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-4298

больше 13 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2011-4298

больше 13 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4297

больше 13 лет назад

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2011-4297

больше 13 лет назад

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2011-4297

больше 13 лет назад

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 do ...

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2011-4296

больше 13 лет назад

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

CVSS2: 5.5
EPSS: Низкий
nvd логотип

CVE-2011-4296

больше 13 лет назад

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

CVSS2: 5.5
EPSS: Низкий
debian логотип

CVE-2011-4296

больше 13 лет назад

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 ...

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4295

больше 13 лет назад

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2011-4295

больше 13 лет назад

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2011-4295

больше 13 лет назад

The moodle_enrol_external:role_assign function in enrol/externallib.ph ...

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-4294

больше 13 лет назад

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2011-4294

больше 13 лет назад

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2011-4294

больше 13 лет назад

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x b ...

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2011-4293

больше 13 лет назад

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2011-4293

больше 13 лет назад

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2011-4293

больше 13 лет назад

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before ...

CVSS2: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2011-4299

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment.

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4299

Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Mo ...

CVSS2: 4.3
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4298

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4298

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4298

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki ...

CVSS2: 6.8
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4297

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

CVSS2: 6.4
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4297

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

CVSS2: 6.4
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4297

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 do ...

CVSS2: 6.4
1%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4296

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4296

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4296

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 ...

CVSS2: 5.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4295

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4295

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4295

The moodle_enrol_external:role_assign function in enrol/externallib.ph ...

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4294

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors.

CVSS2: 5.8
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4294

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors.

CVSS2: 5.8
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4294

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x b ...

CVSS2: 5.8
0%
Низкий
больше 13 лет назад
ubuntu логотип
CVE-2011-4293

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.

CVSS2: 6.4
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2011-4293

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.

CVSS2: 6.4
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2011-4293

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before ...

CVSS2: 6.4
0%
Низкий
больше 13 лет назад

Уязвимостей на страницу