Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
moodle moodle 1.4.1 vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2004-1425
Directory traversal vulnerability in file.php in Moodle 1.4.2 and previous versions allows remote malicious users to read arbitrary session files for known session IDs via a .. (dot dot) in the file parameter.
Moodle Moodle 1.1.1
Moodle Moodle 1.3.4
Moodle Moodle 1.4.1
Moodle Moodle 1.3.0
Moodle Moodle 1.3.1
Moodle Moodle 1.2.0
Moodle Moodle 1.2.1
Moodle Moodle 1.4.2
Moodle Moodle 1.3.2
Moodle Moodle 1.3.3
4.6
CVSSv2
CVE-2013-3630
Moodle up to and including 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
Moodle Moodle 2.5.0
Moodle Moodle 2.4.1
Moodle Moodle 2.3.8
Moodle Moodle 2.3.1
Moodle Moodle 2.2.9
Moodle Moodle 2.2.2
Moodle Moodle 2.2.10
Moodle Moodle 2.1.7
Moodle Moodle 2.1.5
Moodle Moodle 2.0.9
Moodle Moodle 2.0.7
Moodle Moodle 2.0.0
Moodle Moodle 1.9.8
Moodle Moodle 1.9.3
Moodle Moodle 1.9.18
Moodle Moodle 1.9.11
Moodle Moodle 1.9.1
Moodle Moodle 1.8.4
Moodle Moodle 1.8.2
Moodle Moodle 1.8.10
Moodle Moodle 1.6.7
Moodle Moodle 1.6.0
1 EDB exploit
1 Metasploit module
4.3
CVSSv2
CVE-2010-2479
Cross-site scripting (XSS) vulnerability in HTML Purifier prior to 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Htmlpurifier Htmlpurifier
Htmlpurifier Htmlpurifier 3.1.0
Htmlpurifier Htmlpurifier 2.1.3
Htmlpurifier Htmlpurifier 2.1.0
Htmlpurifier Htmlpurifier 1.4.1
Htmlpurifier Htmlpurifier 1.4.0
Htmlpurifier Htmlpurifier 1.3.2
Htmlpurifier Htmlpurifier 3.3.0
Htmlpurifier Htmlpurifier 3.2.0
Htmlpurifier Htmlpurifier 3.0.0
Htmlpurifier Htmlpurifier 2.1.5
Htmlpurifier Htmlpurifier 2.1.2
Htmlpurifier Htmlpurifier 2.1.1
Htmlpurifier Htmlpurifier 2.0.0
Htmlpurifier Htmlpurifier 1.6.1
Htmlpurifier Htmlpurifier 1.1.1
Htmlpurifier Htmlpurifier 1.1.0
Htmlpurifier Htmlpurifier 1.0.1
Htmlpurifier Htmlpurifier 1.0.0
Htmlpurifier Htmlpurifier 4.0.0
Htmlpurifier Htmlpurifier 3.1.1
Htmlpurifier Htmlpurifier 2.1.4
4.3
CVSSv2
CVE-2010-2228
Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle prior to 1.8.13 and 1.9.x prior to 1.9.9 allows remote malicious users to inject arbitrary web script or HTML via vectors involving extended characters in a username.
Moodle Moodle 1.1.1
Moodle Moodle 1.2.0
Moodle Moodle 1.4.1
Moodle Moodle 1.4.2
Moodle Moodle 1.5.3
Moodle Moodle 1.5.0
Moodle Moodle 1.6.7
Moodle Moodle 1.6.8
Moodle Moodle 1.2.1
Moodle Moodle 1.3.0
Moodle Moodle 1.4.3
Moodle Moodle 1.4.4
Moodle Moodle 1.6.0
Moodle Moodle 1.6.1
Moodle Moodle 1.7.1
Moodle Moodle 1.8.1
Moodle Moodle 1.8.2
Moodle Moodle 1.8.9
Moodle Moodle 1.8.10
Moodle Moodle 1.3.1
Moodle Moodle 1.3.2
Moodle Moodle 1.4.5
4.3
CVSSv2
CVE-2010-2229
Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle prior to 1.8.13 and 1.9.x prior to 1.9.9 allow remote malicious users to inject arbitrary web script or HTML via unspecified parameters.
Moodle Moodle 1.8.7
Moodle Moodle 1.8.6
Moodle Moodle 1.7.3
Moodle Moodle 1.6.4
Moodle Moodle 1.6.6
Moodle Moodle 1.5.1
Moodle Moodle 1.5.2
Moodle Moodle 1.4.4
Moodle Moodle 1.3.4
Moodle Moodle 1.8.9
Moodle Moodle 1.8.8
Moodle Moodle 1.8.1
Moodle Moodle 1.6.3
Moodle Moodle 1.6.5
Moodle Moodle 1.6.2
Moodle Moodle 1.5
Moodle Moodle 1.4.2
Moodle Moodle 1.4.5
Moodle Moodle 1.2.0
Moodle Moodle 1.1.1
Moodle Moodle
Moodle Moodle 1.8.5
4.3
CVSSv2
CVE-2008-5432
Cross-site scripting (XSS) vulnerability in Moodle prior to 1.6.8, 1.7 prior to 1.7.6, 1.8 prior to 1.8.7, and 1.9 prior to 1.9.3 allows remote malicious users to inject arbitrary web script or HTML via a Wiki page name (aka page title).
Moodle Moodle 1.6.6
Moodle Moodle 1.6.5
Moodle Moodle 1.5
Moodle Moodle 1.4.5
Moodle Moodle 1.3.2
Moodle Moodle 1.3.1
Moodle Moodle 1.7.4
Moodle Moodle 1.7.3
Moodle Moodle 1.8.4
Moodle Moodle 1.8.5
Moodle Moodle 1.6.4
Moodle Moodle 1.6.3
Moodle Moodle 1.4.4
Moodle Moodle 1.4.3
Moodle Moodle 1.3.0
Moodle Moodle 1.2.1
Moodle Moodle 1.7.2
Moodle Moodle 1.7.1
Moodle Moodle 1.8.6
Moodle Moodle 1.9.0
Moodle Moodle 1.6.1
Moodle Moodle 1.6.0
4.3
CVSSv2
CVE-2008-1502
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare prior to 1.4.003, Moodle prior to 1.8.5, and other products, allows remote malicious users to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string contai...
Moodle Moodle 1.8.1
Moodle Moodle 1.6.7
Moodle Moodle 1.5.0
Moodle Moodle 1.5.3
Moodle Moodle 1.4.2
Moodle Moodle 1.4.1
Moodle Moodle 1.2.0
Moodle Moodle 1.1.1
Moodle Moodle
Moodle Moodle 1.7.4
Moodle Moodle 1.7.3
Moodle Moodle 1.6.4
Moodle Moodle 1.6.3
Moodle Moodle 1.6.2
Moodle Moodle 1.5
Moodle Moodle 1.4.5
Moodle Moodle 1.3.2
Moodle Moodle 1.3.1
Egroupware Egroupware 1.0.3
Egroupware Egroupware 1.0.1
Moodle Moodle 1.7.6
Moodle Moodle 1.7.5
4.3
CVSSv2
CVE-2004-1424
Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the search parameter.
Moodle Moodle 1.2.0
Moodle Moodle 1.2.1
Moodle Moodle 1.4.2
Moodle Moodle 1.3.2
Moodle Moodle 1.3.3
Moodle Moodle 1.3.0
Moodle Moodle 1.3.1
Moodle Moodle 1.1.1
Moodle Moodle 1.3.4
Moodle Moodle 1.4.1
4
CVSSv2
CVE-2010-2230
The KSES text cleaning filter in lib/weblib.php in Moodle prior to 1.8.13 and 1.9.x prior to 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.
Moodle Moodle 1.8.9
Moodle Moodle 1.8.8
Moodle Moodle 1.6.3
Moodle Moodle 1.6.5
Moodle Moodle 1.6.2
Moodle Moodle 1.5
Moodle Moodle 1.5.1
Moodle Moodle 1.4.5
Moodle Moodle 1.4.4
Moodle Moodle 1.2.0
Moodle Moodle 1.1.1
Moodle Moodle
Moodle Moodle 1.8.4
Moodle Moodle 1.8.3
Moodle Moodle 1.7.6
Moodle Moodle 1.7.4
Moodle Moodle 1.6.8
Moodle Moodle 1.6.7
Moodle Moodle 1.5.0
Moodle Moodle 1.4.1
Moodle Moodle 1.3.0
Moodle Moodle 1.3.3
3.5
CVSSv2
CVE-2013-4523
Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle up to and including 2.2.11, 2.3.x prior to 2.3.10, 2.4.x prior to 2.4.7, and 2.5.x prior to 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.
Moodle Moodle 2.5.2
Moodle Moodle 2.4.0
Moodle Moodle 2.4.5
Moodle Moodle 2.3.0
Moodle Moodle 2.3.2
Moodle Moodle 2.3.7
Moodle Moodle 2.2.9
Moodle Moodle 2.2.2
Moodle Moodle 2.2.10
Moodle Moodle 2.1.7
Moodle Moodle 2.1.5
Moodle Moodle 2.5.1
Moodle Moodle 2.4.6
Moodle Moodle 2.3.9
Moodle Moodle 2.3.1
Moodle Moodle 2.3.8
Moodle Moodle 2.2.8
Moodle Moodle 2.2.3
Moodle Moodle
Moodle Moodle 2.1.6
Moodle Moodle 2.1.4
Moodle Moodle 2.0.8
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »