|
269391
|
5.4 |
MEDIUM
Network
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in group/overview.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5269
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269392
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
The rating component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 mishandles group-based authorization checks, which allows remote authenticated users to …
|
CWE-264 CWE-200
Permissions, Privileges, and Access Controls Information Exposure
|
CVE-2015-5268
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269393
|
7.5 |
HIGH
Network
|
moodle
|
moodle
|
lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string…
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2015-5267
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269394
|
6.8 |
MEDIUM
Network
|
moodle
|
moodle
|
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5266
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269395
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5265
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269396
|
5.4 |
MEDIUM
Network
|
moodle
|
moodle
|
The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter addition…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5264
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269397
|
8.8 |
HIGH
Network
|
ibm
|
emptoris_contract_management
|
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.…
|
CWE-352
Origin Validation Error
|
CVE-2015-5050
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269398
|
7.5 |
HIGH
Network
|
ibm
|
emptoris_contract_management
|
IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote attackers…
|
CWE-20
Improper Input Validation
|
CVE-2015-5042
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269399
|
7.5 |
HIGH
Network
|
ibm
|
security_access_manager_for_web_7.0_firmware security_access_manager_for_web_8.0_firmware security_access_manager_9.0_firmware
|
The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms…
|
CWE-310
Cryptographic Issues
|
CVE-2015-5012
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269400
|
7.5 |
HIGH
Network
|
ibm
|
security_access_manager_for_web_8.0_firmware security_access_manager_for_web_7.0_firmware security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid login attempts, which makes it easier for r…
|
CWE-254
7PK - Security Features
|
CVE-2015-5010
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|