Show filters
27 Total Results
Displaying 21-27 of 27
Sort by:
Attacker Value
Unknown
CVE-2009-4297
Disclosure Date: December 16, 2009 (last updated October 04, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-4302
Disclosure Date: December 16, 2009 (last updated October 04, 2023)
login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.
0
Attacker Value
Unknown
CVE-2009-4299
Disclosure Date: December 16, 2009 (last updated October 04, 2023)
mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-4298
Disclosure Date: December 16, 2009 (last updated October 04, 2023)
The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.
0
Attacker Value
Unknown
CVE-2009-4305
Disclosure Date: December 16, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."
0
Attacker Value
Unknown
CVE-2009-4303
Disclosure Date: December 16, 2009 (last updated October 04, 2023)
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2009-4304
Disclosure Date: December 16, 2009 (last updated October 04, 2023)
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.
0