Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 5.0
CVE-2012-4403

theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attack…

Patch available
Fix from $1,600 2012-09-19
Moodle MEDIUM 5.0
CVE-2012-4407

lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files,…

Patch available
Fix from $1,600 2012-09-19
Moodle MEDIUM 6.5
CVE-2012-3395

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote auth…

Mitigation only
Fix from $1,600 2012-07-23
Moodle MEDIUM 5.5
CVE-2012-3392

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote a…

Mitigation only
Fix from $1,600 2012-07-23
Moodle MEDIUM 5.0
CVE-2012-3394

auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an h…

Mitigation only
Fix from $1,600 2012-07-23
Moodle MEDIUM 6.5
CVE-2012-2359

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privilege…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 6.5
CVE-2012-2363

SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to e…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.5
CVE-2012-2366

mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.5
CVE-2012-2358

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and m…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.0
CVE-2012-2357

The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.5
CVE-2011-4589

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege…

Patch available
Fix from $1,600 2012-07-20
Moodle MEDIUM 5.0
CVE-2011-4588

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass i…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 5.0
CVE-2011-4592

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might all…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 6.8
CVE-2011-4587

lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the passw…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 6.5
CVE-2011-4583

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have a…

Patch available
Fix from $1,600 2012-07-20
Moodle MEDIUM 5.0
CVE-2011-4585

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, whi…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 5.0
CVE-2011-4586

CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 …

Mitigation only
Fix from $1,600 2012-07-20
Moodle HIGH 7.5
CVE-2012-0801

lib/formslib.php in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 does not properly handle multiple instances of a form element, which has unspeci…

Mitigation only
Fix from $1,950 2012-07-17
Moodle MEDIUM 6.5
CVE-2012-0795

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows re…

Mitigation only
Fix from $1,600 2012-07-17
Moodle MEDIUM 5.5
CVE-2012-0797

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass th…

Fix: after 2.1.3
Fix from $1,600 2012-07-17
Moodle MEDIUM 5.5
CVE-2012-0798

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by …

Mitigation only
Fix from $1,600 2012-07-17
Moodle MEDIUM 5.0
CVE-2012-0793

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbi…

Mitigation only
Fix from $1,600 2012-07-17
Moodle MEDIUM 5.0
CVE-2012-0794

The rc4encrypt function in lib/moodlelib.php in Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 uses a har…

Mitigation only
Fix from $1,600 2012-07-17
Moodle MEDIUM 6.5
CVE-2011-4295

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authoriz…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.4
CVE-2011-4293

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScrip…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.4
CVE-2011-4297

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.8
CVE-2011-4294

The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link re…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.5
CVE-2011-4296

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote …

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.8
CVE-2011-4133

Cross-site request forgery (CSRF) vulnerability in Moodle 1.9.x before 1.9.11 allows remote attackers to hijack the authentication of unspecified vic…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.8
CVE-2011-4281

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x before 2.0.2 allow remote attackers to hijack the authentication of arbitr…

Mitigation only
Fix from $1,600 2012-07-16