Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moodle MEDIUM 6.8
CVE-2011-4287

admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote att…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.5
CVE-2011-4285

The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authentic…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4279

Moodle 2.0.x before 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote attacke…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4283

Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to …

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4284

Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context …

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.0
CVE-2011-4309

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by levera…

Mitigation only
Fix from $1,600 2012-07-11
Moodle MEDIUM 6.8
CVE-2011-4298

Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote a…

Patch available
Fix from $1,600 2012-07-11
Moodle MEDIUM 6.8
CVE-2011-4302

mnet/xmlrpc/client.php in MNET in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not properly process the return value o…

Patch available
Fix from $1,600 2012-07-11
Moodle MEDIUM 5.0
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which a…

Patch available
Fix from $1,600 2012-07-11
Moodle MEDIUM 5.0
CVE-2011-4301

The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not…

Mitigation only
Fix from $1,600 2012-07-11
Moodle MEDIUM 5.0
CVE-2011-4203

CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and…

No fix yet
Fix from $1,600 2011-12-22
Moodle MEDIUM 5.0
CVE-2011-3757

Moodle 2.0.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e…

No fix yet
Fix from $1,600 2011-09-23
Moodle MEDIUM 6.8
CVE-2010-2231

Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow…

Fix: after 1.8.12
Fix from $1,600 2010-06-28
Moodle HIGH 7.5
CVE-2010-1615

Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands …

Mitigation only
Fix from $1,950 2010-04-29
Moodle MEDIUM 6.8
CVE-2010-1613

Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote att…

Mitigation only
Fix from $1,600 2010-04-29
Moodle HIGH 7.5
CVE-2009-4304

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute…

Patch available
Fix from $1,950 2009-12-16
Moodle MEDIUM 6.8
CVE-2009-4297

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the auth…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 6.5
CVE-2009-4305

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitra…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 6.0
CVE-2009-4301

mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remo…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 5.0
CVE-2009-4298

The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within t…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 5.0
CVE-2009-4299

mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which a…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 5.0
CVE-2009-4300

Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, ev…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 5.0
CVE-2009-4302

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an H…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 5.0
CVE-2009-4303

Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers t…

Patch available
Fix from $1,600 2009-12-16
Moodle HIGH 7.5
CVE-2008-6124

SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before…

Fix: 1.6.7 / 1.7.5+
Fix from $1,950 2009-02-13
Moodle MEDIUM 6.5
CVE-2008-6125

Unspecified vulnerability in the user editing interface in Moodle 1.5.x, 1.6 before 1.6.6, and 1.7 before 1.7.3 allows remote authenticated users to …

Fix: 1.6.6 / 1.7.3+
Fix from $1,600 2009-02-13
Moodle MEDIUM 6.4
CVE-2009-0499

Cross-site request forgery (CSRF) vulnerability in the forum code in Moodle 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before 1.9.4 allows remote at…

Mitigation only
Fix from $1,600 2009-02-10
Moodle MEDIUM 5.0
CVE-2009-0501

Unspecified vulnerability in the Calendar export feature in Moodle 1.8 before 1.8.8 and 1.9 before 1.9.4 allows attackers to obtain sensitive informa…

No fix yet
Fix from $1,600 2009-02-10
Moodle MEDIUM 6.9
CVE-2008-5153

spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2)…

No fix yet
Fix from $1,600 2008-11-18
Moodle MEDIUM 6.0
CVE-2008-3325

Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to modify profile setting…

Fix: 1.6.7 / 1.7.5+
Fix from $1,600 2008-07-25