Moodle

Moodle

601 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.57%
  • Published 13.03.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd parameter to (1) admin/utfdbmigrate.php or (2) filter.php.

Exploit
  • EPSS 0.52%
  • Published 18.12.2006 11:28:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the navtail parameter. NOTE: The provenance of this information is unknown; the details are obtained...

Exploit
  • EPSS 0.85%
  • Published 18.12.2006 11:28:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element. NOTE: The provenance of this information is...

Exploit
  • EPSS 1.65%
  • Published 10.10.2006 04:06:00
  • Last modified 09.04.2025 00:30:58

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

  • EPSS 0.38%
  • Published 23.09.2006 00:07:00
  • Last modified 03.04.2025 01:03:51

The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

  • EPSS 0.38%
  • Published 23.09.2006 00:07:00
  • Last modified 03.04.2025 01:03:51

Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote attack vectors.

  • EPSS 0.24%
  • Published 23.09.2006 00:07:00
  • Last modified 03.04.2025 01:03:51

lib/setup.php in Moodle before 1.6.2 sets the error reporting level to 7 to display E_WARNING messages to users even if debugging is disabled, which might allow remote authenticated users to obtain sensitive information by triggering the messages.

  • EPSS 0.24%
  • Published 23.09.2006 00:07:00
  • Last modified 03.04.2025 01:03:51

help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.

  • EPSS 0.34%
  • Published 23.09.2006 00:07:00
  • Last modified 03.04.2025 01:03:51

backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might allow attackers to obtain the pathname.

  • EPSS 0.33%
  • Published 23.09.2006 00:07:00
  • Last modified 03.04.2025 01:03:51

login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail addresses and Moodle account names) via a find action.