Show filters
104 Total Results
Displaying 71-80 of 104
Sort by:
Attacker Value
Unknown
CVE-2012-2358
Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.
0
Attacker Value
Unknown
CVE-2012-2353
Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.
0
Attacker Value
Unknown
CVE-2012-2359
Disclosure Date: July 21, 2012 (last updated October 04, 2023)
admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.
0
Attacker Value
Unknown
CVE-2012-2366
Disclosure Date: July 21, 2012 (last updated October 04, 2023)
mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-4589
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action.
0
Attacker Value
Unknown
CVE-2011-4584
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.
0
Attacker Value
Unknown
CVE-2011-4582
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
Open redirect vulnerability in the Calendar set page in Moodle 2.1.x before 2.1.3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a redirection URL.
0
Attacker Value
Unknown
CVE-2011-4590
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.
0
Attacker Value
Unknown
CVE-2011-4586
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-4587
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.
0