Show filters
83 Total Results
Displaying 71-80 of 83
Sort by:
Attacker Value
Unknown

CVE-2012-5471

Disclosure Date: November 21, 2012 (last updated October 05, 2023)
The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to access the Dropbox of a different user by leveraging an unattended workstation after a logout.
0
Attacker Value
Unknown

CVE-2012-4400

Disclosure Date: September 19, 2012 (last updated October 05, 2023)
repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.
0
Attacker Value
Unknown

CVE-2012-4403

Disclosure Date: September 19, 2012 (last updated October 05, 2023)
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response.
0
Attacker Value
Unknown

CVE-2012-4401

Disclosure Date: September 19, 2012 (last updated October 05, 2023)
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.
0
Attacker Value
Unknown

CVE-2012-4402

Disclosure Date: September 19, 2012 (last updated October 05, 2023)
webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run arbitrary external-service functions via a token intended for only one service.
0
Attacker Value
Unknown

CVE-2012-4407

Disclosure Date: September 19, 2012 (last updated October 05, 2023)
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.
0
Attacker Value
Unknown

CVE-2012-4408

Disclosure Date: September 19, 2012 (last updated October 05, 2023)
course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass intended access restrictions via a reset operation.
0
Attacker Value
Unknown

CVE-2012-3397

Disclosure Date: July 23, 2012 (last updated October 04, 2023)
lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.
0
Attacker Value
Unknown

CVE-2012-3387

Disclosure Date: July 23, 2012 (last updated October 04, 2023)
Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.
0
Attacker Value
Unknown

CVE-2012-3396

Disclosure Date: July 23, 2012 (last updated November 08, 2023)
Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.
0