Looking for the vulnerability index of Invicti's legacy products?
Moodle Improper Access Control Vulnerability (CVE-2015-2267) - Vulnerability Database

Moodle Improper Access Control Vulnerability (CVE-2015-2267)

Description

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.

References