Show filters
94 Total Results
Displaying 81-90 of 94
Sort by:
Attacker Value
Unknown

CVE-2012-2367

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.
0
Attacker Value
Unknown

CVE-2012-2358

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.
0
Attacker Value
Unknown

CVE-2012-2353

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.
0
Attacker Value
Unknown

CVE-2012-2359

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.
0
Attacker Value
Unknown

CVE-2012-2366

Disclosure Date: July 21, 2012 (last updated October 04, 2023)
mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-0801

Disclosure Date: July 17, 2012 (last updated October 04, 2023)
lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.
0
Attacker Value
Unknown

CVE-2012-0797

Disclosure Date: July 17, 2012 (last updated October 04, 2023)
The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.
0
Attacker Value
Unknown

CVE-2012-0796

Disclosure Date: July 17, 2012 (last updated October 04, 2023)
class.phpmailer.php in the PHPMailer library, as used in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 and other products, allows remote authenticated users to inject arbitrary e-mail headers via vectors involving a crafted (1) From: or (2) Sender: header.
0
Attacker Value
Unknown

CVE-2012-0794

Disclosure Date: July 17, 2012 (last updated October 04, 2023)
The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by reading this script's source code within the open-source software distribution.
0
Attacker Value
Unknown

CVE-2012-0798

Disclosure Date: July 17, 2012 (last updated October 04, 2023)
The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.
0