|
272511
|
- |
|
moodle
|
moodle
|
files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3181
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272512
|
- |
|
moodle
|
moodle
|
lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by le…
|
CWE-200
Information Exposure
|
CVE-2015-3180
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272513
|
- |
|
moodle
|
moodle
|
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3179
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272514
|
- |
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows re…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3178
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272515
|
- |
|
moodle
|
moodle
|
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sen…
|
CWE-17
Code
|
CVE-2015-3177
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272516
|
- |
|
moodle
|
moodle
|
The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name in…
|
CWE-200
Information Exposure
|
CVE-2015-3176
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272517
|
- |
|
moodle
|
moodle
|
Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and con…
|
NVD-CWE-Other
|
CVE-2015-3175
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272518
|
- |
|
moodle
|
moodle
|
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to c…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3174
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272519
|
- |
|
zenphoto
|
zenphoto
|
Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2949
|
2024-11-21 11:28 |
2015-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272520
|
- |
|
zenphoto
|
zenphoto
|
Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2948
|
2024-11-21 11:28 |
2015-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|