Page 21 of 212 results (0.007 seconds)

CVSS: 10.0EPSS: 0%CPEs: 15EXPL: 0

12 Jul 2005 — Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors. • http://moodle.org/doc/?frame=release.html •

CVSS: 6.1EPSS: 0%CPEs: 10EXPL: 1

31 Dec 2004 — Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter. • http://marc.info/?l=bugtraq&m=110425409614735&w=2 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 0%CPEs: 10EXPL: 1

31 Dec 2004 — Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter. • http://marc.info/?l=bugtraq&m=110425409614735&w=2 •

CVSS: 9.8EPSS: 0%CPEs: 9EXPL: 0

31 Dec 2004 — SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements. • http://cvs.sourceforge.net/viewcvs.py/moodle/moodle/mod/glossary/sql.php?r1=1.15.2.2&amp%3Br2=1.15.2.3 •

CVSS: 10.0EPSS: 0%CPEs: 5EXPL: 0

31 Dec 2004 — Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors. • http://moodle.org/doc/?file=releaseold.html •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

31 Dec 2004 — Unknown vulnerability in Moodle before 1.2 allows teachers to log in as administrators. • http://moodle.org/doc/?file=releaseold.html •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

31 Dec 2004 — Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text. • http://moodle.org/doc/?file=releaseold.html •

CVSS: 10.0EPSS: 0%CPEs: 6EXPL: 0

31 Dec 2004 — Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting. • http://moodle.org/doc/?file=releaseold.html •

CVSS: 10.0EPSS: 0%CPEs: 7EXPL: 0

31 Dec 2004 — Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts." • http://moodle.org/doc/?file=releaseold.html •

CVSS: 6.1EPSS: 0%CPEs: 7EXPL: 2

06 Aug 2004 — Cross-site scripting (XSS) vulnerability in post.php in Moodle before 1.3 allows remote attackers to inject arbitrary web script or HTML via the reply parameter. • http://marc.info/?l=bugtraq&m=109182851216921&w=2 •