Search

Found 265 results in 55ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2014-3549 medium 4.3 moodle 12y ago Cross-site scripting (XSS) vulnerability in the get_description function in lib/classes/event/user_login_failed.php in Moodle 2.7.x before 2.7.1 allows remote attackers to inject arbitrary web script…
CVE-2014-3548 medium 4.3 moodle 12y ago Moodle multiple cross-site scripting (XSS) vulnerabilities
CVE-2014-3547 medium 4.3 moodle 12y ago Moodle multiple cross-site scripting (XSS) vulnerabilities
CVE-2014-3546 medium 5.0 moodle 12y ago Moodle allows attackers to obtain username and course information
CVE-2014-3545 medium 6.0 moodle 12y ago Moodle remote code execution via quiz questions
CVE-2014-3543 medium 4.3 moodle 12y ago Moodle Arbitrary File Read via XML External Entity vulnerability
CVE-2014-3542 medium 4.3 moodle 12y ago Moodle allows remote attackers to read arbitrary files
CVE-2014-3541 high 7.5 moodle 12y ago Moodle vulnerable to PHP object injection attacks
CVE-2014-0218 medium 4.3 moodle 12y ago Moodle cross-site scripting (XSS) vulnerability
CVE-2014-0217 medium 4.3 moodle 12y ago Moodle does not check for the moodle/course:viewhiddencourses capability
CVE-2014-0216 medium 5.0 moodle 12y ago Moodle does not properly restrict file access
CVE-2014-0215 medium 4.0 moodle 12y ago Moodle Reveals Student Information Meant To Be Anonymous
CVE-2014-0214 medium 6.8 moodle 12y ago Moodle creates a MoodleMobile web-service token with an infinite lifetime
CVE-2014-0213 medium 6.8 moodle 12y ago Moodle multiple cross-site request forgery (CSRF) vulnerabilities
CVE-2014-2572 medium 4.0 moodle 12y ago Moodle attackers to modify grade metadata
CVE-2014-0129 medium 4.0 moodle 12y ago Moodle allows attackers to modify the visibility of a badge
CVE-2014-0127 medium 4.9 moodle 12y ago Moodle's time-validation implementation allows bypassing intended restrictions
CVE-2014-0126 medium 6.8 moodle 12y ago Moodle cross-site request forgery (CSRF) vulnerability
CVE-2014-0125 medium 5.8 moodle 12y ago Moodle places a session key in a URL
CVE-2014-0124 medium 4.0 moodle 12y ago Moodle allows attackers to obtain sensitive information
CVE-2014-0123 medium 4.9 moodle 12y ago Moodle does not properly restrict access
CVE-2014-0122 medium 4.9 moodle 12y ago Moodle allows bypass of intended access restrictions
CVE-2013-7341 medium 4.3 flowplayermoodle 12y ago Moodle cross-site scripting (XSS) vulnerabilities
CVE-2014-0010 medium 6.8 fedora fedora moodle 13y ago Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allo…
CVE-2014-0009 medium 5.5 moodle 13y ago course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requiremen…
CVE-2014-0008 medium 4.0 moodle 13y ago lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitiv…
CVE-2013-4524 medium 6.8 moodle 13y ago Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read …
CVE-2013-4522 medium 5.0 moodle 13y ago Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2013-3630 medium 5.6 EXP moodle 13y ago Moodle Authenticated Spelling Binary Remote Code Execution
CVE-2013-5674 high 7.5 moodle 13y ago badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object i…
CVE-2013-4341 medium 5.3 EXP moodle 13y ago Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or H…
CVE-2013-4313 high 7.5 moodle 13y ago Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injec…
CVE-2012-6087 medium 5.8 moodle 13y ago repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name i…
CVE-2013-4942 medium 4.3 moodleyahoo 13y ago YUI Cross-site Scripting (XSS) vulnerability
CVE-2013-4941 medium 4.3 moodleyahoo 13y ago YUI Cross-site Scripting (XSS) vulnerability
CVE-2013-4940 medium 4.3 moodleyahoo 13y ago YUI Cross-site Scripting (XSS) vulnerability
CVE-2013-4939 medium 4.3 moodleyahoo 13y ago Cross-Site Scripting in yui
CVE-2013-4938 medium 4.3 moodle 13y ago The LTI (aka IMS-LTI) mod_form implementation in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly support the sendname, sen…
CVE-2013-2246 medium 4.0 moodle 13y ago mod/feedback/lib.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/feedback:view capability before displaying…
CVE-2013-2245 medium 4.0 moodle 13y ago rss/file.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not properly implement the use of RSS tokens for impersonation, which a…
CVE-2013-2244 medium 4.3 moodle 13y ago Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the c…
CVE-2013-2243 medium 4.0 moodle 13y ago mod/lesson/pagetypes/matching.php in Moodle through 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 allows remote authenticated users to obtain sensitive answer information by …
CVE-2013-2242 medium 4.0 moodle 13y ago mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before auth…
CVE-2013-2083 medium 5.0 moodle 13y ago Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class
CVE-2013-2082 medium 5.0 moodle 13y ago Moodle does not enforce capability requirements for reading blog comments
CVE-2013-2081 medium 4.3 moodle 13y ago Moodle does not consider "don't send" attributes during hub registration
CVE-2013-2080 medium 4.0 moodle 13y ago Moodle is vulnerable to Sensitive Information Disclosure
CVE-2013-2079 medium 4.0 moodle 13y ago mod/assign/locallib.php in the assignment module in Moodle 2.3.x before 2.3.7 and 2.4.x before 2.4.4 does not consider capability requirements during the processing of ZIP assignment-archive download…
CVE-2013-1836 medium 6.5 moodle 13y ago Moodle does not properly manage privileges for WebDAV repositories
CVE-2013-1834 medium 4.0 moodle 13y ago Moodle allows remote authenticated users to reassign notes
CVE-2013-1832 medium 4.0 moodle 13y ago Moodle includes the WebDAV password in the configuration form
CVE-2013-1831 medium 5.0 moodle 13y ago Moodle reveals absolute path in exception message
CVE-2013-1830 medium 5.0 fedora fedora moodle 13y ago Moodle does not enforce the forceloginforprofiles setting
CVE-2013-1829 medium 4.0 moodle 13y ago calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain pot…
CVE-2012-6112 medium 5.0 FIX debian debian tinymcemoodle 14y ago classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x be…
CVE-2012-6106 medium 5.5 moodle 14y ago calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calen…
CVE-2012-6105 medium 5.0 moodle 14y ago blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed after blogging is disabled, which allows remote atta…
CVE-2012-6104 medium 5.0 moodle 14y ago blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from site-level blogs by leveraging the guest role and…
CVE-2012-6103 medium 6.8 moodle 14y ago Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote atta…
CVE-2012-6102 medium 6.4 moodle 14y ago lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to read or modify the submission comments (aka feedback …
CVE-2012-6101 medium 5.8 moodle 14y ago Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing at…
CVE-2012-6100 medium 4.0 moodle 14y ago report/outline/index.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/user:viewhiddendetails capability requirement, which allows remo…
CVE-2012-6099 medium 4.0 moodle 14y ago Moodle Arbitrary File Read via Backup Functionality
CVE-2012-6098 medium 4.0 moodle 14y ago grade/edit/outcome/edit_form.php in Moodle 1.9.x through 1.9.19, 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly enforce the moodle/grade:manage …
CVE-2012-5481 medium 4.0 moodle 14y ago Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.
CVE-2012-5480 medium 6.4 moodle 14y ago The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended restrictions on reading other participants' entries vi…
CVE-2012-5479 medium 6.5 moodle 14y ago The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute files via a modified Portfolio API callback.
CVE-2012-5473 medium 4.0 moodle 14y ago The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to read activity entries of a different group's users via an ad…
CVE-2012-5472 medium 4.0 moodle 14y ago lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.
CVE-2012-5471 medium 6.5 moodle 14y ago Moodle Allows Unauthenticated Dropbox Access
CVE-2012-4408 medium 5.5 moodle 14y ago course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, which allows remote authenticated users to bypass …
CVE-2012-4407 medium 5.0 moodle 14y ago lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive…
CVE-2012-4403 medium 5.0 moodle 14y ago theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a r…
CVE-2012-4402 medium 4.9 moodle 14y ago webservice/lib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly restrict the use of web-service tokens, which allows remote authenticated users to run ar…
CVE-2012-4401 medium 4.0 moodle 14y ago Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabiliti…
CVE-2012-4400 medium 4.0 moodle 14y ago repository/repository_ajax.php in Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended upload-size restrictions via a -1 value in the maxbytes field.
CVE-2012-3398 medium 4.0 moodle 14y ago Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU…
CVE-2012-3397 medium 4.0 moodle 14y ago lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity…
CVE-2012-3395 medium 6.5 moodle 14y ago SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands …
CVE-2012-3394 medium 5.0 moodle 14y ago auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows r…
CVE-2012-3392 medium 5.5 moodle 14y ago mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription re…
CVE-2012-3391 medium 4.0 moodle 14y ago mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to…
CVE-2012-3389 medium 4.3 moodle 14y ago Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via …
CVE-2012-3388 medium 4.0 moodle 14y ago The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to …
CVE-2012-3387 medium 4.0 moodle 14y ago Moodle Authentication Bypass in File Upload
CVE-2012-2367 medium 4.0 moodle 14y ago Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and …
CVE-2012-2366 medium 5.5 moodle 14y ago mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity pr…
CVE-2012-2363 medium 6.5 moodle 14y ago SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calend…
CVE-2012-2359 medium 6.5 moodle 14y ago admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying the…
CVE-2012-2358 medium 5.5 moodle 14y ago Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role …
CVE-2012-2357 medium 5.0 moodle 14y ago The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allo…
CVE-2012-2356 medium 4.0 moodle 14y ago Moodle Authentication Bypass in Question-Bank
CVE-2012-2355 medium 4.0 moodle 14y ago Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.
CVE-2012-2354 medium 4.0 moodle 14y ago Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent co…
CVE-2012-2353 medium 4.0 moodle 14y ago Moodle Exposes Sensitive User Information
CVE-2011-4593 medium 4.0 moodle 14y ago Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses …
CVE-2011-4592 medium 5.0 moodle 14y ago The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address …
CVE-2011-4591 medium 4.3 moodle 14y ago Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remo…
CVE-2011-4590 medium 4.0 moodle 14y ago The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows re…
CVE-2011-4589 medium 5.5 moodle 14y ago backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allow…