NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 10756 | CVE-2011-4287 | admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user. | 2 | 6.8 | Medium | 2017-01-07 | 2012-07-16 | View | |
| 10757 | CVE-2011-4288 | Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role. | 2 | 4 | Medium | 2017-01-07 | 2012-07-16 | View | |
| 10758 | CVE-2011-4289 | Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page. | 2 | 4 | Medium | 2017-01-07 | 2012-07-16 | View | |
| 10759 | CVE-2011-4290 | Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding. | 2 | 4.3 | Medium | 2017-01-07 | 2012-07-16 | View | |
| 10760 | CVE-2011-4291 | Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations. | 2 | 4 | Medium | 2017-01-07 | 2012-07-16 | View |
Page 2152 of 17672, showing 5 records out of 88360 total, starting on record 10756, ending on 10760