Search

Found 290 results in 104ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2012-3390 low 3.5 moodle 14y ago lib/filelib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly restrict file access after a block has been hidden, which allows remote authenticated users to obtain sensitive i…
CVE-2012-3389 medium 4.3 moodle 14y ago Multiple cross-site scripting (XSS) vulnerabilities in mod/lti/typessettings.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via …
CVE-2012-3388 medium 4.0 moodle 14y ago The is_enrolled function in lib/accesslib.php in Moodle 2.2.x before 2.2.4 and 2.3.x before 2.3.1 does not properly interact with the caching feature, which might allow remote authenticated users to …
CVE-2012-3387 medium 4.0 moodle 14y ago Moodle Authentication Bypass in File Upload
CVE-2012-2367 medium 4.0 moodle 14y ago Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and …
CVE-2012-2366 medium 5.5 moodle 14y ago mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity pr…
CVE-2012-2365 low 3.5 moodle 14y ago Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnu…
CVE-2012-2364 low 3.5 moodle 14y ago Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script o…
CVE-2012-2363 medium 6.5 moodle 14y ago SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calend…
CVE-2012-2362 low 2.6 moodle 14y ago Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web scri…
CVE-2012-2361 low 3.5 moodle 14y ago Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authen…
CVE-2012-2360 low 3.5 moodle 14y ago Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web scrip…
CVE-2012-2359 medium 6.5 moodle 14y ago admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying the…
CVE-2012-2358 medium 5.5 moodle 14y ago Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role …
CVE-2012-2357 medium 5.0 moodle 14y ago The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allo…
CVE-2012-2356 medium 4.0 moodle 14y ago Moodle Authentication Bypass in Question-Bank
CVE-2012-2355 medium 4.0 moodle 14y ago Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.
CVE-2012-2354 medium 4.0 moodle 14y ago Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent co…
CVE-2012-2353 medium 4.0 moodle 14y ago Moodle Exposes Sensitive User Information
CVE-2011-4593 medium 4.0 moodle 14y ago Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses …
CVE-2011-4592 medium 5.0 moodle 14y ago The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address …
CVE-2011-4591 medium 4.3 moodle 14y ago Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remo…
CVE-2011-4590 medium 4.0 moodle 14y ago The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows re…
CVE-2011-4589 medium 5.5 moodle 14y ago backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allow…
CVE-2011-4588 medium 5.0 moodle 14y ago The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC requ…
CVE-2011-4587 medium 6.8 moodle 14y ago lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attac…
CVE-2011-4586 medium 5.0 moodle 14y ago CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP h…
CVE-2011-4585 medium 5.0 moodle 14y ago login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials b…
CVE-2011-4584 medium 4.0 moodle 14y ago The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login…
CVE-2011-4583 medium 6.5 moodle 14y ago Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated us…
CVE-2011-4582 medium 4.9 moodle 14y ago Moodle Open Redirect in Calendar Set Page
CVE-2011-4581 medium 4.0 moodle 14y ago mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interfa…
CVE-2012-0801 high 7.5 moodle 14y ago lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspecified impact and remote attack vectors.
CVE-2012-0800 low 2.1 moodle 14y ago The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the …
CVE-2012-0799 medium 4.3 moodle 14y ago Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.
CVE-2012-0798 medium 5.5 moodle 14y ago The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by leveraging the teacher role.
CVE-2012-0797 medium 5.5 moodle 14y ago Moodle Users Can Bypass Deleted Status
CVE-2012-0796 medium 4.0 moodle 14y ago PHPMailer vulnerable to email header injection
CVE-2012-0795 medium 6.5 moodle 14y ago Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified im…
CVE-2012-0794 medium 5.0 moodle 14y ago The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a hardcoded password of nfgjeingjk, which makes it easi…
CVE-2012-0793 medium 5.0 moodle 14y ago Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbitrary user accounts via unspecified vectors.
CVE-2012-0792 medium 4.0 moodle 14y ago mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.
CVE-2011-4297 medium 6.4 moodle 14y ago Moodle does not properly restrict comment capabilities
CVE-2011-4296 medium 5.5 moodle 14y ago lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by le…
CVE-2011-4295 medium 6.5 moodle 14y ago The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated use…
CVE-2011-4294 medium 5.8 moodle 14y ago Moodle Open Redirect Via Error Messages
CVE-2011-4293 medium 6.4 moodle 14y ago Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory
CVE-2011-4292 medium 4.0 moodle 14y ago Moodle allows remote authenticated users to cause a denial of service (invalid database records)
CVE-2011-4291 medium 4.0 moodle 14y ago Moodle allows remote authenticated users to cause a denial of service (invalid database records)
CVE-2011-4290 medium 4.3 moodle 14y ago Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.
CVE-2011-4289 medium 4.0 moodle 14y ago Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members
CVE-2011-4288 medium 4.0 moodle 14y ago Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary stude…
CVE-2011-4287 medium 6.8 moodle 14y ago Moodle does not force password changes for autosubscribed users
CVE-2011-4286 medium 4.3 moodle 14y ago Moodle vulnerable to Cross-site Scripting
CVE-2011-4285 medium 5.5 moodle 14y ago Moodle Incorrect Default Settings
CVE-2011-4284 medium 5.0 moodle 14y ago Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context page
CVE-2011-4283 medium 5.0 moodle 14y ago Moodle allows remote attackers to obtain sensitive information
CVE-2011-4282 medium 4.3 moodle 14y ago Moodle vulnerable to Cross-site Scripting
CVE-2011-4281 medium 6.8 moodle 14y ago Moodle vulnerable to Cross-Site Request Forgery
CVE-2011-4280 medium 5.3 EXP moodlenimish_pachapurkar 14y ago Moodle vulnerable to XSS via bundled spikephpcoverage library
CVE-2011-4279 medium 5.0 moodle 14y ago Moodle does not use the forceloginforprofiles setting for course-profiles access control
CVE-2011-4278 medium 4.3 moodle 14y ago Moodle XSS In Tag Autocomplete functionality
CVE-2011-4133 medium 6.8 moodle 14y ago Moodle vulnerable to Cross-Site Request Forgery
CVE-2011-4309 medium 5.0 moodle 14y ago Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to…
CVE-2011-4308 medium 4.0 moodle 14y ago mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
CVE-2011-4307 medium 4.3 moodle 14y ago Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the sectio…
CVE-2011-4306 medium 4.3 moodle 14y ago Moodle XSS Vulnerability
CVE-2011-4305 medium 4.0 moodle 14y ago message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshi…
CVE-2011-4304 medium 4.0 moodle 14y ago The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
CVE-2011-4303 medium 4.3 moodle 14y ago lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended ac…
CVE-2011-4302 medium 6.8 moodle 14y ago mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote…
CVE-2011-4301 medium 5.0 moodle 14y ago Moodle Allows Modification of Constants
CVE-2011-4300 medium 5.0 moodle 14y ago Moodle does not properly restrict access to category and course data
CVE-2011-4299 medium 4.3 moodle 14y ago Moodle vulnerable to Cross-Site Scripting
CVE-2011-4298 medium 6.8 moodle 14y ago Moodle vulnerable to Cross-Site Request Forgery
CVE-2011-4203 medium 5.0 moodle 15y ago Moodle CRLF Injection Vulnerability in Calendar Component
CVE-2011-3757 medium 5.0 moodle 15y ago Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc…
CVE-2010-4208 medium 4.3 yahoomoodlemozilla 16y ago Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary…
CVE-2010-4207 medium 4.3 yahoomoodlemozilla 16y ago Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary…
CVE-2010-2231 medium 6.8 moodle 16y ago Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of…
CVE-2010-2230 medium 4.0 FIX debian debian moodle 16y ago The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site sc…
CVE-2010-2229 medium 4.3 moodle 16y ago Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified para…
CVE-2010-2228 medium 4.3 moodle 16y ago Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors…
CVE-2010-1619 medium 4.3 FIX debian debian moodle 16y ago Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, a…
CVE-2010-1618 medium 4.3 ja-sigmoodle 16y ago phpCAS client library and Moodle Cross-site Scripting vulnerability
CVE-2010-1617 medium 4.0 moodle 16y ago Moodle doesn't properly check role
CVE-2010-1616 medium 4.0 moodle 16y ago Moodle is vulnerable to unauthorized new accounts creation
CVE-2010-1615 high 7.5 moodle 16y ago Moodle vulnerable to SQL injection
CVE-2010-1614 medium 4.3 moodle 16y ago Moodle vulnerable to Cross-site Scripting
CVE-2010-1613 medium 6.8 moodle 16y ago Moodle Session Fixation vulnerability