NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
10975  CVE-2011-4587  lib/moodlelib.php in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle certain zero values in the password policy, which makes it easier for remote attackers to obtain access by leveraging the possible existence of user accounts that have unchangeable blank passwords.    6.8  Medium  2017-01-07  2012-07-20  View
10974  CVE-2011-4586  CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.    Medium  2017-01-07  2012-07-20  View
10973  CVE-2011-4585  login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.    Medium  2017-01-07  2012-07-20  View
10972  CVE-2011-4584  The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.    Medium  2017-01-07  2012-07-20  View
10971  CVE-2011-4583  Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.    6.5  Medium  2017-01-07  2013-08-12  View

Page 15478 of 17672, showing 5 records out of 88360 total, starting on record 77386, ending on 77390

Actions