The following Moodle application is publicly accessible and looks out-dated :
It is highly recommended to update to a safe version as soon as possible since multiple CVEs allow remote attackers to craft XSS attacks leading to code execution on the server.
If the application was already patched, reloading the web server to clear the PHP opcache will fix issue.
Reference:
Severity: high
Fingerprint: 0b591a20d83e9bbda3370ce58008084480080844800808448008084480080844
Found vulnerable Moodle application: Affected by CVE-2023-30943
Open service 130.193.51.253:80 · moodle.test.home.pik-digital.ru
2024-12-21 07:21
HTTP/1.1 308 Permanent Redirect Date: Sat, 21 Dec 2024 07:21:02 GMT Content-Type: text/html Content-Length: 164 Connection: close Location: https://moodle.test.home.pik-digital.ru Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-12-21 07:21
HTTP/1.1 200 OK Date: Sat, 21 Dec 2024 07:21:05 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=kv7cqqvnhmbaqj3j9v3qgi2slp; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Sat, 21 Dec 2024 07:21:05 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-12-20 15:08
HTTP/1.1 200 OK Date: Fri, 20 Dec 2024 15:08:50 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=2vcppfihtj0c7e7rs31q0ij200; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Fri, 20 Dec 2024 15:08:50 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-12-18 19:39
HTTP/1.1 200 OK Date: Wed, 18 Dec 2024 19:39:39 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=0qgl7p7o1ha2to153db4bp3mf9; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Wed, 18 Dec 2024 19:39:39 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-12-14 08:49
HTTP/1.1 200 OK Date: Sat, 14 Dec 2024 08:49:28 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=tiaonibhpucmqume65nkv9qg7r; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Sat, 14 Dec 2024 08:49:28 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-12-12 14:28
HTTP/1.1 200 OK Date: Thu, 12 Dec 2024 14:28:24 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=0492nblkenmlibjl8rgraust65; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Thu, 12 Dec 2024 14:28:24 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-12-02 09:03
HTTP/1.1 200 OK Date: Mon, 02 Dec 2024 09:03:48 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=bh27bu232c6om3tc4ppj8gh2q6; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Mon, 02 Dec 2024 09:03:48 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-11-30 05:40
HTTP/1.1 200 OK Date: Sat, 30 Nov 2024 05:40:05 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=p8avmki4ooa87h993vhv32tuuv; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Sat, 30 Nov 2024 05:40:05 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-11-28 20:47
HTTP/1.1 200 OK Date: Thu, 28 Nov 2024 20:47:11 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=sha95ct9dmdg378345ijijrqkm; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Thu, 28 Nov 2024 20:47:11 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-11-26 17:40
HTTP/1.1 200 OK Date: Tue, 26 Nov 2024 17:40:12 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=anp2t4r585a9ac7dsgrl5uqbbh; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Tue, 26 Nov 2024 17:40:12 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains
Open service 130.193.51.253:443 · moodle.test.home.pik-digital.ru
2024-11-20 17:42
HTTP/1.1 200 OK Date: Wed, 20 Nov 2024 17:42:14 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Set-Cookie: MoodleSession=rk9pcfr9q1oc2pv2dprdve013r; path=/; secure Expires: Mon, 20 Aug 1969 09:23:00 GMT Cache-Control: no-store, no-cache, must-revalidate Pragma: no-cache Content-Language: ru Content-Script-Type: text/javascript Content-Style-Type: text/css X-UA-Compatible: IE=edge Cache-Control: post-check=0, pre-check=0, no-transform Last-Modified: Wed, 20 Nov 2024 17:42:14 GMT Accept-Ranges: none X-Frame-Options: sameorigin Vary: Accept-Encoding Strict-Transport-Security: max-age=15724800; includeSubDomains