Vulnerability index

Browse CVEs

69 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 6.5
CVE-2012-2359

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privilege…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 6.5
CVE-2012-2363

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to e…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.5
CVE-2012-2366

mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.5
CVE-2012-2358

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and m…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.0
CVE-2012-2357

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.0
CVE-2011-4588

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass i…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 5.0
CVE-2011-4592

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might all…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 6.8
CVE-2011-4587

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the passw…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 5.0
CVE-2011-4585

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, whi…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 5.0
CVE-2011-4586

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 …

Mitigation only
Fix from $1,600 2012-07-20
Moodle HIGH 7.5
CVE-2012-0801

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspeci…

Mitigation only
Fix from $1,950 2012-07-17
Moodle MEDIUM 6.5
CVE-2012-0795

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows re…

Mitigation only
Fix from $1,600 2012-07-17
Moodle MEDIUM 5.5
CVE-2012-0798

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by …

Mitigation only
Fix from $1,600 2012-07-17
Moodle MEDIUM 5.0
CVE-2012-0793

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbi…

Mitigation only
Fix from $1,600 2012-07-17
Moodle MEDIUM 5.0
CVE-2012-0794

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a har…

Mitigation only
Fix from $1,600 2012-07-17
Moodle MEDIUM 6.5
CVE-2011-4295

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authoriz…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.4
CVE-2011-4293

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScrip…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.4
CVE-2011-4297

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.8
CVE-2011-4294

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link re…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.5
CVE-2011-4296

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote …

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.8
CVE-2011-4133

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified vic…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.8
CVE-2011-4281

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitr…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.8
CVE-2011-4287

admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote att…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.5
CVE-2011-4285

The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authentic…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4279

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attacke…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4283

Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to …

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4284

Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context …

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4309

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by levera…

Mitigation only
Fix from $1,600 2012-07-11
Moodle MEDIUM 5.0
CVE-2011-4301

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not…

Mitigation only
Fix from $1,600 2012-07-11
Moodle MEDIUM 5.0
CVE-2011-4203

CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and…

No fix yet
Fix from $1,600 2011-12-22