NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 10770 | CVE-2011-4301 | The MoodleQuickForm class in the Forms Library in lib/formslib.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 does not recognize Forms API setConstant operations, which allows remote attackers to submit unexpected form content by modifying the values of constant fields. | 2 | 5 | Medium | 2017-01-07 | 2012-07-11 | View | |
| 10769 | CVE-2011-4300 | The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which allows remote attackers to obtain potentially sensitive information via a request for a file. | 2 | 5 | Medium | 2017-01-07 | 2012-07-11 | View | |
| 10768 | CVE-2011-4299 | Cross-site scripting (XSS) vulnerability in mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via a wiki comment. | 2 | 4.3 | Medium | 2017-01-07 | 2012-07-11 | View | |
| 10767 | CVE-2011-4298 | Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data. | 2 | 6.8 | Medium | 2017-01-07 | 2012-07-17 | View | |
| 10766 | CVE-2011-4297 | comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity. | 2 | 6.4 | Medium | 2017-01-07 | 2012-07-16 | View |
Page 15519 of 17672, showing 5 records out of 88360 total, starting on record 77591, ending on 77595