Show filters
58 Total Results
Displaying 11-20 of 58
Sort by:
Attacker Value
Unknown
CVE-2012-2362
Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.
0
Attacker Value
Unknown
CVE-2012-2363
Disclosure Date: July 21, 2012 (last updated October 04, 2023)
SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.
0
Attacker Value
Unknown
CVE-2012-2367
Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.
0
Attacker Value
Unknown
CVE-2011-4585
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.
0
Attacker Value
Unknown
CVE-2011-4584
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
0
Attacker Value
Unknown
CVE-2011-4586
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-4587
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
0
Attacker Value
Unknown
CVE-2011-4593
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.
0
Attacker Value
Unknown
CVE-2011-4588
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request.
0
Attacker Value
Unknown
CVE-2012-0796
Disclosure Date: July 17, 2012 (last updated October 04, 2023)
class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.
0