Show filters
63 Total Results
Displaying 31-40 of 63
Sort by:
Attacker Value
Unknown
CVE-2011-4294
Disclosure Date: July 16, 2012 (last updated October 04, 2023)
The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-4308
Disclosure Date: July 11, 2012 (last updated October 04, 2023)
mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-4301
Disclosure Date: July 11, 2012 (last updated October 04, 2023)
The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields.
0
Attacker Value
Unknown
CVE-2011-4305
Disclosure Date: July 11, 2012 (last updated October 04, 2023)
message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.
0
Attacker Value
Unknown
CVE-2011-4306
Disclosure Date: July 11, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in course/editsection.html in Moodle 1.9.x before 1.9.14 allows remote authenticated users to inject arbitrary web script or HTML via crafted data.
0
Attacker Value
Unknown
CVE-2011-4302
Disclosure Date: July 11, 2012 (last updated October 04, 2023)
mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote attackers to bypass validation via a crafted certificate.
0
Attacker Value
Unknown
CVE-2011-4203
Disclosure Date: December 22, 2011 (last updated October 04, 2023)
CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors involving the url variable.
0
Attacker Value
Unknown
CVE-2010-2228
Disclosure Date: June 28, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors involving extended characters in a username.
0
Attacker Value
Unknown
CVE-2010-2230
Disclosure Date: June 28, 2010 (last updated October 04, 2023)
The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.
0
Attacker Value
Unknown
CVE-2010-2229
Disclosure Date: June 28, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0