Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown
CVE-2010-2231
Disclosure Date: June 28, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of arbitrary users for requests that delete quiz attempts via the attemptid parameter.
0
Attacker Value
Unknown
CVE-2008-5432
Disclosure Date: December 11, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).
0
Attacker Value
Unknown
CVE-2008-1502
Disclosure Date: March 25, 2008 (last updated October 04, 2023)
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.
0
Attacker Value
Unknown
CVE-2005-2247
Disclosure Date: July 12, 2005 (last updated February 22, 2025)
Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2004-1425
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.
0
Attacker Value
Unknown
CVE-2004-2236
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.
0
Attacker Value
Unknown
CVE-2004-2237
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."
0
Attacker Value
Unknown
CVE-2004-2233
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2004-2235
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
0
Attacker Value
Unknown
CVE-2004-1424
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.
0