Vulnerability index

Browse CVEs

69 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 5.0
CVE-2011-3757

Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e…

No fix yet
Fix from $1,600 2011-09-23
Moodle HIGH 7.5
CVE-2010-1615

Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands …

Mitigation only
Fix from $1,950 2010-04-29
Moodle MEDIUM 6.8
CVE-2010-1613

Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote att…

Mitigation only
Fix from $1,600 2010-04-29
Moodle MEDIUM 6.4
CVE-2009-0499

Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote at…

Mitigation only
Fix from $1,600 2009-02-10
Moodle MEDIUM 5.0
CVE-2009-0501

Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive informa…

No fix yet
Fix from $1,600 2009-02-10
Moodle MEDIUM 6.9
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2)…

No fix yet
Fix from $1,600 2008-11-18
Moodle HIGH 7.5
CVE-2007-1429

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd paramete…

Mitigation only
Fix from $1,950 2007-03-13
Moodle MEDIUM 6.8
CVE-2006-6625

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via …

No fix yet
Fix from $1,600 2006-12-18
Moodle MEDIUM 6.8
CVE-2006-6626

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via…

No fix yet
Fix from $1,600 2006-12-18