Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle HIGH 7.8
CVE-2007-1647

Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides directory listings, which all…

Fix: after 1.5.2
Fix from $1,950 2007-03-24
Moodle HIGH 7.5
CVE-2007-1429

Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 allow remote attackers to execute arbitrary PHP code via a URL in the cmd paramete…

Mitigation only
Fix from $1,950 2007-03-13
Moodle MEDIUM 6.8
CVE-2006-6625

Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in Moodle 1.6.1 allows remote attackers to inject arbitrary web script or HTML via …

No fix yet
Fix from $1,600 2006-12-18
Moodle MEDIUM 6.8
CVE-2006-6626

Cross-site scripting (XSS) vulnerability in an unspecified component of Moodle 1.5 allows remote attackers to inject arbitrary web script or HTML via…

No fix yet
Fix from $1,600 2006-12-18
Moodle MEDIUM 5.1
CVE-2006-5219

SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a doub…

Patch available
Fix from $1,600 2006-10-10
Moodle HIGH 10.0
CVE-2006-4935

The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

Fix: after 1.6.1
Fix from $1,950 2006-09-23
Moodle HIGH 10.0
CVE-2006-4936

Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote a…

Fix: after 1.6.1
Fix from $1,950 2006-09-23
Moodle MEDIUM 5.0
CVE-2006-4939

backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debugging is disabled, which might al…

Fix: after 1.6.1
Fix from $1,600 2006-09-23
Moodle MEDIUM 5.0
CVE-2006-4940

login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail addresses and Moodle account names) …

Fix: after 1.6.1
Fix from $1,600 2006-09-23
Moodle MEDIUM 5.0
CVE-2006-4943

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows…

Fix: after 1.6.1
Fix from $1,600 2006-09-23
Moodle HIGH 7.5
CVE-2006-4785

SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and earlier allows remote attackers to execute arbitrary SQL commands via the format par…

Fix: after 1.6.1
Fix from $1,950 2006-09-14
Moodle MEDIUM 5.0
CVE-2006-4786

Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving schedul…

Fix: after 1.6.1
Fix from $1,600 2006-09-14
Moodle HIGH 7.5
CVE-2006-0146EPSS 13%

The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) …

Patch available
Fix from $1,950 2006-01-09
Moodle HIGH 7.5
CVE-2006-0147EPSS 13%

Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis…

Patch available
Fix from $1,950 2006-01-09
Moodle HIGH 7.5
CVE-2005-3648

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL comm…

Patch available
Fix from $1,950 2005-11-17
Moodle HIGH 10.0
CVE-2005-2247

Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.

Patch available
Fix from $1,950 2005-07-12
Moodle HIGH 10.0
CVE-2004-2233

Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.

Patch available
Fix from $1,950 2004-12-31
Moodle HIGH 10.0
CVE-2004-2235

Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.

Patch available
Fix from $1,950 2004-12-31
Moodle HIGH 10.0
CVE-2004-2236

Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.

Patch available
Fix from $1,950 2004-12-31
Moodle HIGH 10.0
CVE-2004-2237

Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."

Patch available
Fix from $1,950 2004-12-31
Moodle HIGH 7.5
CVE-2004-2232

SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.

Patch available
Fix from $1,950 2004-12-31
Moodle MEDIUM 5.0
CVE-2004-1425

Directory traversal vulnerability in file.php in Moodle 1.4.2 and earlier allows remote attackers to read arbitrary session files for known session I…

Patch available
Fix from $1,600 2004-12-31
Moodle MEDIUM 6.8
CVE-2004-0725

Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbitrary web script or HTML via t…

Patch available
Fix from $1,600 2004-07-27