Search

Found 249 results in 47ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2012-0793 medium 5.0 moodle 14y ago Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbitrary user accounts via unspecified vectors.
CVE-2012-0792 medium 4.0 moodle 14y ago mod/forum/user.php in Moodle 1.9.x before 1.9.16 allows remote authenticated users to obtain the names and other details of arbitrary user accounts by searching for posts.
CVE-2011-4297 medium 6.4 moodle 14y ago Moodle does not properly restrict comment capabilities
CVE-2011-4296 medium 5.5 moodle 14y ago lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by le…
CVE-2011-4295 medium 6.5 moodle 14y ago The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated use…
CVE-2011-4294 medium 5.8 moodle 14y ago Moodle Open Redirect Via Error Messages
CVE-2011-4293 medium 6.4 moodle 14y ago Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory
CVE-2011-4292 medium 4.0 moodle 14y ago Moodle allows remote authenticated users to cause a denial of service (invalid database records)
CVE-2011-4291 medium 4.0 moodle 14y ago Moodle allows remote authenticated users to cause a denial of service (invalid database records)
CVE-2011-4290 medium 4.3 moodle 14y ago Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.
CVE-2011-4289 medium 4.0 moodle 14y ago Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members
CVE-2011-4288 medium 4.0 moodle 14y ago Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary stude…
CVE-2011-4287 medium 6.8 moodle 14y ago Moodle does not force password changes for autosubscribed users
CVE-2011-4286 medium 4.3 moodle 14y ago Moodle vulnerable to Cross-site Scripting
CVE-2011-4285 medium 5.5 moodle 14y ago Moodle Incorrect Default Settings
CVE-2011-4284 medium 5.0 moodle 14y ago Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context page
CVE-2011-4283 medium 5.0 moodle 14y ago Moodle allows remote attackers to obtain sensitive information
CVE-2011-4282 medium 4.3 moodle 14y ago Moodle vulnerable to Cross-site Scripting
CVE-2011-4281 medium 6.8 moodle 14y ago Moodle vulnerable to Cross-Site Request Forgery
CVE-2011-4280 medium 5.3 EXP moodlenimish_pachapurkar 14y ago Moodle vulnerable to XSS via bundled spikephpcoverage library
CVE-2011-4279 medium 5.0 moodle 14y ago Moodle does not use the forceloginforprofiles setting for course-profiles access control
CVE-2011-4278 medium 4.3 moodle 14y ago Moodle XSS In Tag Autocomplete functionality
CVE-2011-4133 medium 6.8 moodle 14y ago Moodle vulnerable to Cross-Site Request Forgery
CVE-2011-4309 medium 5.0 moodle 14y ago Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to…
CVE-2011-4308 medium 4.0 moodle 14y ago mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
CVE-2011-4307 medium 4.3 moodle 14y ago Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the sectio…
CVE-2011-4306 medium 4.3 moodle 14y ago Moodle XSS Vulnerability
CVE-2011-4305 medium 4.0 moodle 14y ago message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshi…
CVE-2011-4304 medium 4.0 moodle 14y ago The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
CVE-2011-4303 medium 4.3 moodle 14y ago lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended ac…
CVE-2011-4302 medium 6.8 moodle 14y ago mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value of the openssl_verify function, which allows remote…
CVE-2011-4301 medium 5.0 moodle 14y ago Moodle Allows Modification of Constants
CVE-2011-4300 medium 5.0 moodle 14y ago Moodle does not properly restrict access to category and course data
CVE-2011-4299 medium 4.3 moodle 14y ago Moodle vulnerable to Cross-Site Scripting
CVE-2011-4298 medium 6.8 moodle 14y ago Moodle vulnerable to Cross-Site Request Forgery
CVE-2011-4203 medium 5.0 moodle 15y ago Moodle CRLF Injection Vulnerability in Calendar Component
CVE-2011-3757 medium 5.0 moodle 15y ago Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by webservice/xmlrpc…
CVE-2010-4208 medium 4.3 yahoomoodlemozilla 16y ago Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary…
CVE-2010-4207 medium 4.3 yahoomoodlemozilla 16y ago Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary…
CVE-2010-2231 medium 6.8 moodle 16y ago Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of…
CVE-2010-2230 medium 4.0 FIX debian debian moodle 16y ago The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site sc…
CVE-2010-2229 medium 4.3 moodle 16y ago Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified para…
CVE-2010-2228 medium 4.3 moodle 16y ago Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors…
CVE-2010-1619 medium 4.3 FIX debian debian moodle 16y ago Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, a…
CVE-2010-1618 medium 4.3 ja-sigmoodle 16y ago phpCAS client library and Moodle Cross-site Scripting vulnerability
CVE-2010-1617 medium 4.0 moodle 16y ago Moodle doesn't properly check role
CVE-2010-1616 medium 4.0 moodle 16y ago Moodle is vulnerable to unauthorized new accounts creation
CVE-2010-1614 medium 4.3 moodle 16y ago Moodle vulnerable to Cross-site Scripting
CVE-2010-1613 medium 6.8 moodle 16y ago Moodle Session Fixation vulnerability