Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2010-2231
Disclosure Date: June 28, 2010 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of arbitrary users for requests that delete quiz attempts via the attemptid parameter.
0
Attacker Value
Unknown
CVE-2008-5432
Disclosure Date: December 11, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or HTML via a Wiki page name (aka page title).
0
Attacker Value
Unknown
CVE-2008-1502
Disclosure Date: March 25, 2008 (last updated October 04, 2023)
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.
0
Attacker Value
Unknown
CVE-2005-2247
Disclosure Date: July 12, 2005 (last updated February 22, 2025)
Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.
0