CVE-2013-4524
- EPSS 0.28%
- Veröffentlicht 26.11.2013 05:25:38
- Zuletzt bearbeitet 11.04.2025 00:51:21
Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.
CVE-2013-4525
- EPSS 0.21%
- Veröffentlicht 26.11.2013 05:25:38
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HT...
CVE-2013-3630
- EPSS 64.52%
- Veröffentlicht 01.11.2013 02:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
CVE-2012-6087
- EPSS 0.16%
- Veröffentlicht 16.09.2013 13:02:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName ...
CVE-2013-4313
- EPSS 0.37%
- Veröffentlicht 16.09.2013 13:02:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a cra...
CVE-2013-4341
- EPSS 7.71%
- Veröffentlicht 16.09.2013 13:02:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.
CVE-2013-5674
- EPSS 0.57%
- Veröffentlicht 16.09.2013 13:02:48
- Zuletzt bearbeitet 11.04.2025 00:51:21
badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demons...
- EPSS 0.16%
- Veröffentlicht 29.07.2013 13:59:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authe...
- EPSS 0.18%
- Veröffentlicht 29.07.2013 13:59:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by reading the HTML source code of a document.
CVE-2013-2244
- EPSS 0.26%
- Veröffentlicht 29.07.2013 13:59:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.