Show filters
78 Total Results
Displaying 41-50 of 78
Sort by:
Attacker Value
Unknown

CVE-2012-2359

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.
0
Attacker Value
Unknown

CVE-2011-4589

Disclosure Date: July 20, 2012 (last updated October 04, 2023)
backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.
0
Attacker Value
Unknown

CVE-2011-4584

Disclosure Date: July 20, 2012 (last updated October 04, 2023)
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
0
Attacker Value
Unknown

CVE-2011-4590

Disclosure Date: July 20, 2012 (last updated October 04, 2023)
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.
0
Attacker Value
Unknown

CVE-2011-4586

Disclosure Date: July 20, 2012 (last updated October 04, 2023)
CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-4587

Disclosure Date: July 20, 2012 (last updated October 04, 2023)
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
0
Attacker Value
Unknown

CVE-2011-4593

Disclosure Date: July 20, 2012 (last updated October 04, 2023)
Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.
0
Attacker Value
Unknown

CVE-2011-4592

Disclosure Date: July 20, 2012 (last updated October 04, 2023)
The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.
0
Attacker Value
Unknown

CVE-2011-4581

Disclosure Date: July 20, 2012 (last updated October 04, 2023)
mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.
0
Attacker Value
Unknown

CVE-2011-4583

Disclosure Date: July 20, 2012 (last updated October 04, 2023)
Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.
0