NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 10980 | CVE-2011-4592 | The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality. | 2 | 5 | Medium | 2017-01-07 | 2012-07-20 | View | |
| 10979 | CVE-2011-4591 | Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states. | 2 | 4.3 | Medium | 2017-01-07 | 2012-07-20 | View | |
| 10978 | CVE-2011-4590 | The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server. | 2 | 4 | Medium | 2017-01-07 | 2012-07-23 | View | |
| 10977 | CVE-2011-4589 | backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege during handling of course ID numbers, which allows remote authenticated users to overwrite ID numbers via a restore action. | 2 | 5.5 | Medium | 2017-01-07 | 2012-07-20 | View | |
| 10976 | CVE-2011-4588 | The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass intended IP address restrictions via an XMLRPC request. | 2 | 5 | Medium | 2017-01-07 | 2012-07-20 | View |
Page 15477 of 17672, showing 5 records out of 88360 total, starting on record 77381, ending on 77385