|
270991
|
8.8 |
HIGH
Network
|
moodle
|
moodle
|
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 all…
|
CWE-352
Origin Validation Error
|
CVE-2016-2157
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270992
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an act…
|
CWE-200
Information Exposure
|
CVE-2016-2156
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270993
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allow…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2155
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270994
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows re…
|
CWE-200
Information Exposure
|
CVE-2016-2154
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270995
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allo…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2153
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270996
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote att…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2152
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270997
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhidd…
|
CWE-200
Information Exposure
|
CVE-2016-2151
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270998
|
5.4 |
MEDIUM
Network
|
theforeman
|
foreman
|
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permissi…
|
CWE-284
Improper Access Control
|
CVE-2016-2100
|
2024-11-21 11:47 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270999
|
8.8 |
HIGH
Network
|
apple webkitgtk
|
iphone_os tvos safari webkitgtk\+
|
The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1859
|
2024-11-21 11:47 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271000
|
6.5 |
MEDIUM
Network
|
apple webkitgtk
|
iphone_os tvos safari webkitgtk\+
|
WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted …
|
CWE-200
Information Exposure
|
CVE-2016-1858
|
2024-11-21 11:47 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|