Information on source package moodle

Available versions

ReleaseVersion
squeeze, squeeze1.9.9.dfsg2-2.1+squeeze3
wheezy, sid2.2.2.dfsg-2

Open issues

BugDescription
CVE-2012-1104
CVE-2012-1105

Open unimportant issues

BugDescription
CVE-2006-4976The Date Library in John Lim ADOdb Library for PHP allows remote ...
CVE-2008-0123Cross-site scripting (XSS) vulnerability in install.php for Moodle ...
CVE-2008-3327Moodle 1.6.5, when display_errors is enabled, allows remote attackers ...
CVE-2012-1155

Resolved issues

BugDescription
CVE-2004-0725Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 ...
CVE-2004-1424Cross-site scripting (XSS) vulnerability in view.php in Moodle 1.4.2 ...
CVE-2004-1425Directory traversal vulnerability in file.php in Moodle 1.4.2 and ...
CVE-2004-1711Cross-site scripting (XSS) vulnerability in post.php in Moodle before ...
CVE-2004-1978Cross-site scripting (XSS) vulnerability in help.php in Moodle before ...
CVE-2004-2232SQL injection vulnerability in sql.php in the Glossary module in ...
CVE-2004-2233Unknown "front page vulnerability with Moodle servers" for Moodle ...
CVE-2004-2234Unknown vulnerability in Moodle before 1.2 allows teachers to log in ...
CVE-2004-2235Unknown vulnerability in Moodle before 1.2 has unknown impact and ...
CVE-2004-2236Unknown vulnerability in Moodle before 1.3.3 has unknown impact and ...
CVE-2004-2237Unknown vulnerability in Moodle before 1.3.4 has unknown impact and ...
CVE-2004-2664John Lim ADOdb Library for PHP before 4.23 allows remote attackers to ...
CVE-2005-2247Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown ...
CVE-2005-3648Multiple SQL injection vulnerabilities in the get_record function in ...
CVE-2005-3649jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users ...
CVE-2005-4600Directory traversal vulnerability in tiny_mce_gzip.php in TinyMCE ...
CVE-2006-0146The server.php test script in ADOdb for PHP before 4.70, as used in ...
CVE-2006-0147Dynamic code evaluation vulnerability in tests/tmssql.php test script ...
CVE-2006-0410SQL injection vulnerability in ADOdb before 4.71, when using ...
CVE-2006-0806Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as ...
CVE-2006-4618PHP remote file inclusion vulnerability in adodb-postgres7.inc.php in ...
CVE-2006-4784Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 ...
CVE-2006-4785SQL injection vulnerability in blog/edit.php in Moodle 1.6.1 and ...
CVE-2006-4786Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive ...
CVE-2006-4935The Database module in Moodle before 1.6.2 does not properly handle ...
CVE-2006-4936Moodle before 1.6.2 does not properly validate the module instance id ...
CVE-2006-4937lib/setup.php in Moodle before 1.6.2 sets the error reporting level to ...
CVE-2006-4938help.php in Moodle before 1.6.2 does not check the existence of ...
CVE-2006-4939backup/backup_scheduled.php in Moodle before 1.6.2 generates trace ...
CVE-2006-4940login/forgot_password.php in Moodle before 1.6.2 allows remote ...
CVE-2006-4941Multiple cross-site scripting (XSS) vulnerabilities in Moodle before ...
CVE-2006-4942Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) ...
CVE-2006-4943course/jumpto.php in Moodle before 1.6.2 does not validate the session ...
CVE-2006-5219SQL injection vulnerability in blog/index.php in the blog module in ...
CVE-2006-6625Cross-site scripting (XSS) vulnerability in mod/forum/discuss.php in ...
CVE-2006-6626Cross-site scripting (XSS) vulnerability in an unspecified component ...
CVE-2007-1429Multiple PHP remote file inclusion vulnerabilities in Moodle 1.7.1 ...
CVE-2007-1647Moodle 1.5.2 and earlier stores sensitive information under the web ...
CVE-2007-2326Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro ...
CVE-2007-2385The Yahoo! UI framework exchanges data using JavaScript Object ...
CVE-2007-3215PHPMailer 1.7, when configured to use sendmail, allows remote ...
CVE-2007-3555Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 ...
CVE-2007-6538SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php ...
CVE-2008-1066The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used ...
CVE-2008-1502The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in ...
CVE-2008-3325Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before ...
CVE-2008-3326Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle ...
CVE-2008-4796The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 ...
CVE-2008-4810The _expand_quoted_text function in libs/Smarty_Compiler.class.php in ...
CVE-2008-4811The _expand_quoted_text function in libs/Smarty_Compiler.class.php in ...
CVE-2008-5153spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite ...
CVE-2008-5432Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 ...
CVE-2008-5619html2text.php in Chuggnutt HTML to Text Converter, as used in ...
CVE-2008-6124SQL injection vulnerability in the hotpot_delete_selected_attempts ...
CVE-2008-6125Unspecified vulnerability in the user editing interface in Moodle ...
CVE-2009-0499Cross-site request forgery (CSRF) vulnerability in the forum code in ...
CVE-2009-0500Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle ...
CVE-2009-0501Unspecified vulnerability in the Calendar export feature in Moodle 1.8 ...
CVE-2009-0502Cross-site scripting (XSS) vulnerability in blocks/html/block_html.php ...
CVE-2009-1171The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 ...
CVE-2009-4297Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle ...
CVE-2009-4298The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before ...
CVE-2009-4299mod/glossary/showentry.php in the Glossary module for Moodle 1.8 ...
CVE-2009-4300Multiple unspecified authentication plugins in Moodle 1.8 before ...
CVE-2009-4301mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when ...
CVE-2009-4302login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 ...
CVE-2009-4303Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password ...
CVE-2009-4304Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random ...
CVE-2009-4305SQL injection vulnerability in the SCORM module in Moodle 1.8 before ...
CVE-2010-1613Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate ...
CVE-2010-1614Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.8.x ...
CVE-2010-1615Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 ...
CVE-2010-1616Moodle 1.8.x and 1.9.x before 1.9.8 can create new roles when ...
CVE-2010-1617user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 ...
CVE-2010-1618Cross-site scripting (XSS) vulnerability in the phpCAS client library ...
CVE-2010-1619Cross-site scripting (XSS) vulnerability in the ...
CVE-2010-2228Cross-site scripting (XSS) vulnerability in the MNET access-control ...
CVE-2010-2229Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php ...
CVE-2010-2230The KSES text cleaning filter in lib/weblib.php in Moodle before ...
CVE-2010-2231Cross-site request forgery (CSRF) vulnerability in ...
CVE-2010-2479Cross-site scripting (XSS) vulnerability in HTML Purifier before ...
CVE-2010-2795phpCAS before 1.1.2 allows remote authenticated users to hijack ...
CVE-2010-2796Cross-site scripting (XSS) vulnerability in phpCAS before 1.1.2, when ...
CVE-2010-3690Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before ...
CVE-2010-3691PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is ...
CVE-2010-3692Directory traversal vulnerability in the callback function in ...
CVE-2010-4536Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used ...
CVE-2011-4133MSA-11-0002
CVE-2011-4278MSA-11-0003
CVE-2011-4279MSA-11-0004
CVE-2011-4280MSA-11-0005
CVE-2011-4281MSA-11-0006
CVE-2011-4282MSA-11-0007
CVE-2011-4283MSA-11-0008
CVE-2011-4284MSA-11-0009
CVE-2011-4285MSA-11-0010
CVE-2011-4286MSA-11-0011
CVE-2011-4287MSA-11-0012
CVE-2011-4288MSA-11-0013
CVE-2011-4289MSA-11-0014
CVE-2011-4290MSA-11-0015
CVE-2011-4291MSA-11-0016
CVE-2011-4292MSA-11-0017
CVE-2011-4293MSA-11-0019
CVE-2011-4294MSA-11-0020
CVE-2011-4295MSA-11-0021
CVE-2011-4296MSA-11-0022
CVE-2011-4297MSA-11-0023
CVE-2011-4298MSA-11-0027
CVE-2011-4299MSA-11-0028
CVE-2011-4300MSA-11-0029
CVE-2011-4301MSA-11-0031
CVE-2011-4302MSA-11-0032
CVE-2011-4303MSA-11-0033
CVE-2011-4304MSA-11-0034
CVE-2011-4305MSA-11-0036
CVE-2011-4306MSA-11-0037
CVE-2011-4307MSA-11-0039
CVE-2011-4308MSA-11-0040
CVE-2011-4309MSA-11-0041
CVE-2011-4581
CVE-2011-4582
CVE-2011-4583
CVE-2011-4584
CVE-2011-4585
CVE-2011-4586
CVE-2011-4587
CVE-2011-4588
CVE-2011-4589
CVE-2011-4590
CVE-2011-4591
CVE-2011-4592
CVE-2011-4593
CVE-2012-0792MSA-12-0002: Personal information leak
CVE-2012-0793MSA-12-0004: Added profile image security
CVE-2012-0794MSA-12-0005: Encryption enhancement
CVE-2012-0795MSA-12-0006: Additional email address validation
CVE-2012-0796MSA-12-0007: Email injection prevention
CVE-2012-0797MSA-12-0008: Unsynchronised access via tokens
CVE-2012-0798MSA-12-0009: Role access issue
CVE-2012-0799MSA-12-0010: Unauthorised access to session key
CVE-2012-0800MSA-12-0011: Browser autofill password issue
CVE-2012-0801MSA-12-0012: Form validation issue
CVE-2012-1156
CVE-2012-1157
CVE-2012-1158
CVE-2012-1159
CVE-2012-1160
CVE-2012-1161
CVE-2012-1168
CVE-2012-1169
CVE-2012-1170
TEMP-0000000-5CAA34Unspecified issue in moodle's admin/delete.php
TEMP-0000000-EA71EFmoodle unspecified security bug in the forum module (discuss.php)
TEMP-0495985-D91305tcpdf code execution via tcpdf tag

Security announcements

DSADescription
DSA-2421-1moodle - several
DSA-2338-1moodle - several
DSA-2262-1moodle - several
DSA-2172-1moodle - several
DSA-2115-1moodle - several vulnerabilities
DSA-1986-1moodle - several vulnerabilities
DSA-1761-1moodle - file disclosure
DSA-1761-1moodle - file disclosure
DSA-1724-1- several vulnerabilities
DSA-1691-1moodle - several vulnerabilities
DSA-1030-1moodle - several

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Source (SVN)