|
295721
|
- |
|
moodle
|
moodle
|
lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attac…
|
CWE-255
Credentials Management
|
CVE-2011-4587
|
2024-11-21 10:32 |
2012-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295722
|
- |
|
moodle
|
moodle
|
CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP h…
|
NVD-CWE-Other
|
CVE-2011-4586
|
2024-11-21 10:32 |
2012-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295723
|
- |
|
moodle
|
moodle
|
login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials b…
|
CWE-16
Configuration
|
CVE-2011-4585
|
2024-11-21 10:32 |
2012-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295724
|
- |
|
moodle
|
moodle
|
The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4584
|
2024-11-21 10:32 |
2012-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295725
|
- |
|
moodle
|
moodle
|
Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated us…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4583
|
2024-11-21 10:32 |
2012-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295726
|
- |
|
moodle
|
moodle
|
Open redirect vulnerability in the Calendar set page in Moodle 2.1.x before 2.1.3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a redirec…
|
CWE-20
Improper Input Validation
|
CVE-2011-4582
|
2024-11-21 10:32 |
2012-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295727
|
- |
|
moodle
|
moodle
|
mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interfa…
|
CWE-200
Information Exposure
|
CVE-2011-4581
|
2024-11-21 10:32 |
2012-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295728
|
- |
|
oracle
|
sun_glassfish_enterprise_server
|
Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.0.1 and 3.1.1 allows remote attackers to affect confidentiality and integrity, related to JSF.
|
NVD-CWE-noinfo
|
CVE-2011-4358
|
2024-11-21 10:32 |
2012-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295729
|
- |
|
moodle
|
moodle
|
comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and o…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4297
|
2024-11-21 10:32 |
2012-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295730
|
- |
|
moodle
|
moodle
|
lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by le…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4296
|
2024-11-21 10:32 |
2012-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|