Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 470

Количество 2 470

nvd логотип

CVE-2007-1647

около 18 лет назад

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2007-1647

около 18 лет назад

Moodle 1.5.2 and earlier stores sensitive information under the web ro ...

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-1429

больше 18 лет назад

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-1429

больше 18 лет назад

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2007-1429

больше 18 лет назад

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 all ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-6626

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2006-6626

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2006-6626

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in an unspecified component o ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2006-6625

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2006-6625

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2006-6625

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in M ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2006-5219

больше 18 лет назад

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2006-5219

больше 18 лет назад

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2006-5219

больше 18 лет назад

SQL injection vulnerability in blog/index.php in the blog module in Mo ...

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2006-4943

почти 19 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2006-4943

почти 19 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2006-4943

почти 19 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-4942

почти 19 лет назад

Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2006-4942

почти 19 лет назад

Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php.

CVSS2: 4.6
EPSS: Низкий
debian логотип

CVE-2006-4942

почти 19 лет назад

Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) t ...

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2007-1647

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which allows remote attackers to obtain user names, password hashes, and other sensitive information via a direct request for session (sess_*) files in moodledata/sessions/.

CVSS2: 7.8
3%
Низкий
около 18 лет назад
debian логотип
CVE-2007-1647

Moodle 1.5.2 and earlier stores sensitive information under the web ro ...

CVSS2: 7.8
3%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-1429

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

CVSS2: 7.5
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-1429

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

CVSS2: 7.5
1%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-1429

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 all ...

CVSS2: 7.5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-6626

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-6626

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. NOTE: It is unclear whether this candidate overlaps CVE-2006-4784 or CVE-2006-4941.

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-6626

Cross-site scripting (XSS) vulnerability in an unspecified component o ...

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-6625

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-6625

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-6625

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in M ...

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-5219

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

CVSS2: 5.1
2%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-5219

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

CVSS2: 5.1
2%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-5219

SQL injection vulnerability in blog/index.php in the blog module in Mo ...

CVSS2: 5.1
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-4943

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

CVSS2: 5
0%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-4943

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

CVSS2: 5
0%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-4943

course/jumpto.php in Moodle before 1.6.2 does not validate the session ...

CVSS2: 5
0%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2006-4942

Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php.

CVSS2: 4.6
1%
Низкий
почти 19 лет назад
nvd логотип
CVE-2006-4942

Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to write LaTeX or MimeTeX output files to the top level of the dataroot directory via (a) filter/algebra/pix.php or (b) filter/tex/pix.php.

CVSS2: 4.6
1%
Низкий
почти 19 лет назад
debian логотип
CVE-2006-4942

Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) t ...

CVSS2: 4.6
1%
Низкий
почти 19 лет назад

Уязвимостей на страницу