Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 535

Количество 2 535

nvd логотип

CVE-2008-6124

больше 16 лет назад

SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-6124

больше 16 лет назад

SQL injection vulnerability in the hotpot_delete_selected_attempts fun ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-5432

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5432

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-5432

больше 16 лет назад

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 b ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-5153

больше 16 лет назад

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

CVSS2: 6.9
EPSS: Низкий
redhat логотип

CVE-2008-5153

около 17 лет назад

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

EPSS: Низкий
nvd логотип

CVE-2008-5153

больше 16 лет назад

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2008-5153

больше 16 лет назад

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite ...

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2008-3327

около 17 лет назад

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3327

около 17 лет назад

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3327

около 17 лет назад

Moodle 1.6.5, when display_errors is enabled, allows remote attackers ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3326

около 17 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-3326

около 17 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2008-3326

около 17 лет назад

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1. ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2008-3325

около 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2008-3325

около 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2008-3325

около 17 лет назад

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before ...

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2008-0123

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-0123

больше 17 лет назад

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-6124

SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.

CVSS2: 7.5
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-6124

SQL injection vulnerability in the hotpot_delete_selected_attempts fun ...

CVSS2: 7.5
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-5432

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
nvd логотип
CVE-2008-5432

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-5432

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 b ...

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

CVSS2: 6.9
0%
Низкий
больше 16 лет назад
redhat логотип
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

CVSS2: 6.9
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite ...

CVSS2: 6.9
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2008-3327

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

CVSS2: 4.3
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-3327

Moodle 1.6.5, when display_errors is enabled, allows remote attackers to obtain sensitive information via a direct request to (1) blog/blogpage.php and (2) course/report/stats/report.php, which reveals the installation path in an error message.

CVSS2: 4.3
0%
Низкий
около 17 лет назад
debian логотип
CVE-2008-3327

Moodle 1.6.5, when display_errors is enabled, allows remote attackers ...

CVSS2: 4.3
0%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-3326

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-3326

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS2: 2.6
1%
Низкий
около 17 лет назад
debian логотип
CVE-2008-3326

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1. ...

CVSS2: 2.6
1%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.

CVSS2: 6
0%
Низкий
около 17 лет назад
debian логотип
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before ...

CVSS2: 6
0%
Низкий
около 17 лет назад
ubuntu логотип
CVE-2008-0123

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-0123

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад

Уязвимостей на страницу