Show filters
104 Total Results
Displaying 81-90 of 104
Sort by:
Attacker Value
Unknown
CVE-2011-4593
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.
0
Attacker Value
Unknown
CVE-2011-4592
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.
0
Attacker Value
Unknown
CVE-2011-4581
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.
0
Attacker Value
Unknown
CVE-2011-4583
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.
0
Attacker Value
Unknown
CVE-2011-4591
Disclosure Date: July 20, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.
0
Attacker Value
Unknown
CVE-2012-0801
Disclosure Date: July 17, 2012 (last updated October 04, 2023)
lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.
0
Attacker Value
Unknown
CVE-2012-0796
Disclosure Date: July 17, 2012 (last updated October 04, 2023)
class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.
0
Attacker Value
Unknown
CVE-2012-0794
Disclosure Date: July 17, 2012 (last updated October 04, 2023)
The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.
0
Attacker Value
Unknown
CVE-2012-0798
Disclosure Date: July 17, 2012 (last updated October 04, 2023)
The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.
0
Attacker Value
Unknown
CVE-2012-0793
Disclosure Date: July 17, 2012 (last updated October 04, 2023)
Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbitrary user accounts via unspecified vectors.
0