Show filters
86 Total Results
Displaying 71-80 of 86
Sort by:
Attacker Value
Unknown

CVE-2012-3394

Disclosure Date: July 23, 2012 (last updated October 04, 2023)
auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.
0
Attacker Value
Unknown

CVE-2012-3388

Disclosure Date: July 23, 2012 (last updated October 04, 2023)
The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to bypass an intended capability check via unspecified vectors that trigger caching of a user record.
0
Attacker Value
Unknown

CVE-2012-3390

Disclosure Date: July 23, 2012 (last updated October 04, 2023)
lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive information by reading a file that is embedded in a block.
0
Attacker Value
Unknown

CVE-2012-2364

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.
0
Attacker Value
Unknown

CVE-2012-2361

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.
0
Attacker Value
Unknown

CVE-2012-2354

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.
0
Attacker Value
Unknown

CVE-2012-2357

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.
0
Attacker Value
Unknown

CVE-2012-2356

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.
0
Attacker Value
Unknown

CVE-2012-2355

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.
0
Attacker Value
Unknown

CVE-2012-2360

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.
0