Show filters
34 Total Results
Displaying 21-30 of 34
Sort by:
Attacker Value
Unknown

CVE-2009-4297

Disclosure Date: December 16, 2009 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-4302

Disclosure Date: December 16, 2009 (last updated October 04, 2023)
login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.
0
Attacker Value
Unknown

CVE-2009-4299

Disclosure Date: December 16, 2009 (last updated October 04, 2023)
mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-4298

Disclosure Date: December 16, 2009 (last updated October 04, 2023)
The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-4305

Disclosure Date: December 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."
0
Attacker Value
Unknown

CVE-2009-4303

Disclosure Date: December 16, 2009 (last updated October 04, 2023)
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2009-4304

Disclosure Date: December 16, 2009 (last updated October 04, 2023)
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.
0
Attacker Value
Unknown

CVE-2009-1171

Disclosure Date: March 30, 2009 (last updated October 04, 2023)
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.
0
Attacker Value
Unknown

CVE-2009-0501

Disclosure Date: February 10, 2009 (last updated October 04, 2023)
Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive information and conduct "brute force attacks on user accounts" via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-0500

Disclosure Date: February 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle 1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote attackers to inject arbitrary web script or HTML via crafted log table information that is not properly handled when it is displayed in a log report.
0