Show filters
72 Total Results
Displaying 61-70 of 72
Sort by:
Attacker Value
Unknown
CVE-2012-6102
Disclosure Date: January 27, 2013 (last updated October 05, 2023)
lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback comments) of arbitrary users via a crafted URI.
0
Attacker Value
Unknown
CVE-2012-6100
Disclosure Date: January 27, 2013 (last updated October 05, 2023)
report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remote authenticated users to discover a hidden lastaccess value by reading an activity report.
0
Attacker Value
Unknown
CVE-2012-6104
Disclosure Date: January 27, 2013 (last updated October 05, 2023)
blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and reading an RSS feed.
0
Attacker Value
Unknown
CVE-2012-6099
Disclosure Date: January 27, 2013 (last updated October 05, 2023)
The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.
0
Attacker Value
Unknown
CVE-2012-6105
Disclosure Date: January 27, 2013 (last updated October 05, 2023)
blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote attackers to obtain sensitive information by reading this feed.
0
Attacker Value
Unknown
CVE-2012-6098
Disclosure Date: January 27, 2013 (last updated October 05, 2023)
grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage capability requirement, which allows remote authenticated users to convert custom outcomes into standard site-wide outcomes by leveraging the teacher role and using the re-editing feature.
0
Attacker Value
Unknown
CVE-2012-5473
Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an advanced search.
0
Attacker Value
Unknown
CVE-2012-5472
Disclosure Date: November 21, 2012 (last updated October 05, 2023)
lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.
0
Attacker Value
Unknown
CVE-2012-5480
Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries via an advanced search.
0
Attacker Value
Unknown
CVE-2012-5479
Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.
0