|
272521
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attacke…
|
CWE-200
Information Exposure
|
CVE-2016-2158
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272522
|
8.8 |
HIGH
Network
|
moodle
|
moodle
|
Cross-site request forgery (CSRF) vulnerability in mod/assign/adminmanageplugins.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 all…
|
CWE-352
Origin Validation Error
|
CVE-2016-2157
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272523
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an act…
|
CWE-200
Information Exposure
|
CVE-2016-2156
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272524
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
The grade-reporting feature in Singleview (aka Single View) in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/grade:manage capability, which allow…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2155
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272525
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
admin/tool/monitor/lib.php in Event Monitor in Moodle 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not consider the moodle/course:viewhiddencourses capability, which allows re…
|
CWE-200
Information Exposure
|
CVE-2016-2154
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272526
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in the advanced-search feature in mod_data in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allo…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2153
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272527
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Multiple cross-site scripting (XSS) vulnerabilities in auth/db/auth.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allow remote att…
|
CWE-79
Cross-site Scripting
|
CVE-2016-2152
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272528
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
user/index.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 grants excessive authorization on the basis of the moodle/course:viewhidd…
|
CWE-200
Information Exposure
|
CVE-2016-2151
|
2024-11-21 11:47 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272529
|
5.4 |
MEDIUM
Network
|
theforeman
|
foreman
|
Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destroy_bookmarks permissi…
|
CWE-284
Improper Access Control
|
CVE-2016-2100
|
2024-11-21 11:47 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272530
|
8.8 |
HIGH
Network
|
apple webkitgtk
|
iphone_os tvos safari webkitgtk\+
|
The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1859
|
2024-11-21 11:47 |
2016-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|