CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2012-3391

    Last Modified: 11 Apr 2025

    mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the student role and reading the RSS feed for a forum.

    Published: 23 Jul 2012
    5.5
    Medium

    CVE-2012-3392

    Last Modified: 11 Apr 2025

    mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.

    Published: 23 Jul 2012
    6.5
    Medium

    CVE-2012-3395

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

    Published: 23 Jul 2012
    4
    Medium

    CVE-2012-3397

    Last Modified: 11 Apr 2025

    lib/modinfolib.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 does not check for a group-membership requirement when determining whether an activity is unavailable or hidden, which allows remote authenticated users to bypass intended access restrictions by selecting an activity that is configured for a group of other users.

    Published: 23 Jul 2012
    5
    Medium

    CVE-2012-3394

    Last Modified: 11 Apr 2025

    auth/ldap/ntlmsso_attempt.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 redirects users from an https LDAP login URL to an http URL, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 23 Jul 2012
    3.5
    Low

    CVE-2012-3396

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in cohort/edit_form.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, 2.2.x before 2.2.4, and 2.3.x before 2.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the idnumber field. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2365.

    Published: 23 Jul 2012
    4
    Medium

    CVE-2012-3398

    Last Modified: 11 Apr 2025

    Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a database activity that has many records.

    Published: 23 Jul 2012
    3.5
    Low

    CVE-2012-3393

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in repository/lib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 allows remote authenticated administrators to inject arbitrary web script or HTML by renaming a repository.

    Published: 23 Jul 2012
    10
    Critical

    CVE-2012-2953

    Last Modified: 11 Apr 2025

    The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.

    Published: 23 Jul 2012
    7.5
    High

    CVE-2012-2961

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Jul 2012
    10
    Critical

    CVE-2012-2976

    Last Modified: 11 Apr 2025

    The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" issue.

    Published: 23 Jul 2012
    7.5
    High

    CVE-2012-2574

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to a "blind SQL injection" issue.

    Published: 23 Jul 2012
    4.4
    Medium

    CVE-2012-0305

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Symantec System Recovery 2011 before SP2 and Backup Exec System Recovery 2010 before SP5 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 23 Jul 2012
    7.2
    High

    CVE-2012-2957

    Last Modified: 11 Apr 2025

    The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inclusion" issue.

    Published: 23 Jul 2012
    5
    Medium

    CVE-2012-2977

    Last Modified: 11 Apr 2025

    The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an application script.

    Published: 23 Jul 2012
    2.1
    Low

    CVE-2012-3430

    Last Modified: 11 Apr 2025

    The rds_recvmsg function in net/rds/recv.c in the Linux kernel before 3.0.44 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) recvfrom or (2) recvmsg system call on an RDS socket.

    Published: 23 Jul 2012
    1.9
    Low

    CVE-2012-2737

    Last Modified: 11 Apr 2025

    The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.

    Published: 22 Jul 2012
    2.6
    Low

    CVE-2012-3383

    Last Modified: 11 Apr 2025

    The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

    Published: 22 Jul 2012
    6.8
    Medium

    CVE-2012-3384

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the customizer in WordPress before 3.4.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 22 Jul 2012
    7.5
    High

    CVE-2012-4045

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in bmp.w5s in Winamp before 5.63 build 3235 allow remote attackers to execute arbitrary code via the (1) strf chunk in BI_RGB or (2) UYVY video data in an AVI file, or (3) decompressed TechSmith Screen Capture Codec (TSCC) data in an AVI file.

    Published: 22 Jul 2012
    5
    Medium

    CVE-2012-3385

    Last Modified: 11 Apr 2025

    WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors to obtain sensitive information via unknown vectors.

    Published: 22 Jul 2012
    5
    Medium

    CVE-2012-3356

    Last Modified: 11 Apr 2025

    The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 22 Jul 2012
    5
    Medium

    CVE-2012-3357

    Last Modified: 11 Apr 2025

    The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a "log msg leak."

    Published: 22 Jul 2012
    5.5
    Medium

    CVE-2012-3360

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authenticated users to write arbitrary files to the disk image via a .. (dot dot) in the path attribute of a file element.

    Published: 22 Jul 2012
    5.5
    Medium

    CVE-2012-3361

    Last Modified: 11 Apr 2025

    virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary files via a symlink attack on a file in an image.

    Published: 22 Jul 2012
    4.3
    Medium

    CVE-2009-5031

    Last Modified: 11 Apr 2025

    ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.

    Published: 22 Jul 2012
    4.3
    Medium

    CVE-2012-2751

    Last Modified: 11 Apr 2025

    ModSecurity before 2.6.6, when used with PHP, does not properly handle single quotes not at the beginning of a request parameter value in the Content-Disposition field of a request with a multipart/form-data Content-Type header, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-5031.

    Published: 22 Jul 2012
    3.3
    Low

    CVE-2012-4048

    Last Modified: 11 Apr 2025

    The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via a crafted packet, as demonstrated by a usbmon dump.

    Published: 22 Jul 2012
    2.9
    Low

    CVE-2012-4049

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (loop and CPU consumption) via a crafted packet.

    Published: 22 Jul 2012
    4
    Medium

    CVE-2012-2353

    Last Modified: 11 Apr 2025

    Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to obtain sensitive user information from hidden fields by leveraging the teacher role and navigating to "Enrolled users" under the Users Settings section.

    Published: 21 Jul 2012
    4
    Medium

    CVE-2012-2354

    Last Modified: 11 Apr 2025

    Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.

    Published: 21 Jul 2012
    4
    Medium

    CVE-2012-2355

    Last Modified: 11 Apr 2025

    Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass question:use* capability requirements and add arbitrary questions to a quiz via the questions feature.

    Published: 21 Jul 2012
    4
    Medium

    CVE-2012-2356

    Last Modified: 11 Apr 2025

    The question-bank functionality in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass intended capability requirements and save questions via a save_question action.

    Published: 21 Jul 2012
    6.5
    Medium

    CVE-2012-2359

    Last Modified: 11 Apr 2025

    admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privileges by leveraging the teacher role and modifying their own capabilities, as demonstrated by obtaining the backup:userinfo capability.

    Published: 21 Jul 2012
    3.5
    Low

    CVE-2012-2360

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Wiki subsystem in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is inserted into a page title.

    Published: 21 Jul 2012
    3.5
    Low

    CVE-2012-2361

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/webservice/forms.php in the web services implementation in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the name field (aka the service name) to admin/webservice/service.php.

    Published: 21 Jul 2012
    2.6
    Low

    CVE-2012-2362

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in blog/lib.php in the blog implementation in Moodle 1.9.x before 1.9.18, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted parameter to blog/index.php.

    Published: 21 Jul 2012
    6.5
    Medium

    CVE-2012-2363

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.

    Published: 21 Jul 2012
    3.5
    Low

    CVE-2012-2364

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in lib/filelib.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via an assignment submission with zip compression, leading to text/html rendering during a "download all" action.

    Published: 21 Jul 2012
    5.5
    Medium

    CVE-2012-2358

    Last Modified: 11 Apr 2025

    Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and modify the database by leveraging the student role and editing database activity entries that already exist.

    Published: 21 Jul 2012
    5.5
    Medium

    CVE-2012-2366

    Last Modified: 11 Apr 2025

    mod/data/preset.php in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not properly iterate through an array, which allows remote authenticated users to overwrite arbitrary database activity presets via unspecified vectors.

    Published: 21 Jul 2012
    5
    Medium

    CVE-2012-2357

    Last Modified: 11 Apr 2025

    The Multi-Authentication feature in the Central Authentication Service (CAS) functionality in auth/cas/cas_form.html in Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 does not use HTTPS, which allows remote attackers to obtain credentials by sniffing the network.

    Published: 21 Jul 2012
    3.5
    Low

    CVE-2012-2365

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to inject arbitrary web script or HTML via the idnumber field to cohort/edit.php.

    Published: 21 Jul 2012
    4
    Medium

    CVE-2012-2367

    Last Modified: 11 Apr 2025

    Moodle 1.9.x before 1.9.18, 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

    Published: 21 Jul 2012
    4
    Medium

    CVE-2011-4581

    Last Modified: 11 Apr 2025

    mod/wiki/pagelib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 allows remote authenticated users to discover the username of a wiki creator by visiting the history and deletion user interface.

    Published: 20 Jul 2012
    4.9
    Medium

    CVE-2011-4582

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Calendar set page in Moodle 2.1.x before 2.1.3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a redirection URL.

    Published: 20 Jul 2012
    6.5
    Medium

    CVE-2011-4583

    Last Modified: 11 Apr 2025

    Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.

    Published: 20 Jul 2012
    4
    Medium

    CVE-2011-4584

    Last Modified: 11 Apr 2025

    The MNET authentication functionality in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote authenticated users to impersonate other user accounts by using the Login As feature in conjunction with a remote MNET single sign-on capability, as demonstrated by a Mahara site.

    Published: 20 Jul 2012
    5
    Medium

    CVE-2011-4585

    Last Modified: 11 Apr 2025

    login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.

    Published: 20 Jul 2012
    5
    Medium

    CVE-2011-4586

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 20 Jul 2012