Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown

CVE-2013-4524

Disclosure Date: November 26, 2013 (last updated October 05, 2023)
Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.
0
Attacker Value
Unknown

CVE-2013-4523

Disclosure Date: November 26, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.
0
Attacker Value
Unknown

CVE-2013-4522

Disclosure Date: November 26, 2013 (last updated October 05, 2023)
lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.
0
Attacker Value
Unknown

CVE-2013-4525

Disclosure Date: November 26, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.
0
Attacker Value
Unknown

CVE-2013-3630

Disclosure Date: November 01, 2013 (last updated October 05, 2023)
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
0
Attacker Value
Unknown

CVE-2013-1830

Disclosure Date: March 25, 2013 (last updated October 05, 2023)
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.
0
Attacker Value
Unknown

CVE-2013-1831

Disclosure Date: March 25, 2013 (last updated October 05, 2023)
lib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the absolute path in an exception message.
0
Attacker Value
Unknown

CVE-2010-2228

Disclosure Date: June 28, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors involving extended characters in a username.
0
Attacker Value
Unknown

CVE-2010-2230

Disclosure Date: June 28, 2010 (last updated October 04, 2023)
The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.
0
Attacker Value
Unknown

CVE-2010-2229

Disclosure Date: June 28, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0