Moodle

Moodle

601 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.57%
  • Veröffentlicht 13.03.2007 01:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

Exploit
  • EPSS 0.52%
  • Veröffentlicht 18.12.2006 11:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained...

Exploit
  • EPSS 0.85%
  • Veröffentlicht 18.12.2006 11:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is...

Exploit
  • EPSS 1.65%
  • Veröffentlicht 10.10.2006 04:06:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

  • EPSS 0.38%
  • Veröffentlicht 23.09.2006 00:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

  • EPSS 0.38%
  • Veröffentlicht 23.09.2006 00:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.

  • EPSS 0.24%
  • Veröffentlicht 23.09.2006 00:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

lib/setup.php in Moodle before 1.6.2 sets the error reporting level to 7 to display E_WARNING messages to users even if debugging is disabled, which might allow remote authenticated users to obtain sensitive information by triggering the messages.

  • EPSS 0.24%
  • Veröffentlicht 23.09.2006 00:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.

  • EPSS 0.34%
  • Veröffentlicht 23.09.2006 00:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname.

  • EPSS 0.33%
  • Veröffentlicht 23.09.2006 00:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail addresses and Moodle account names) via a find action.