CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-4282

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the course-tags functionality in tag/coursetags_more.php in Moodle 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) sort or (2) show parameter.

    Published: 16 Jul 2012
    5
    Medium

    CVE-2011-4283

    Last Modified: 11 Apr 2025

    Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to obtain sensitive information via a request for imsenterprise-enrol.xml.

    Published: 16 Jul 2012
    6.8
    Medium

    CVE-2011-4287

    Last Modified: 11 Apr 2025

    admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote attackers to obtain access by leveraging knowledge of the initial password of a new user.

    Published: 16 Jul 2012
    4
    Medium

    CVE-2011-4288

    Last Modified: 11 Apr 2025

    Moodle 1.9.x before 1.9.12 and 2.0.x before 2.0.3 does not properly implement associations between teachers and groups, which allows remote authenticated users to read quiz reports of arbitrary students by leveraging the teacher role.

    Published: 16 Jul 2012
    4
    Medium

    CVE-2011-4289

    Last Modified: 11 Apr 2025

    Moodle 2.0.x before 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.

    Published: 16 Jul 2012
    4.3
    Medium

    CVE-2011-4290

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.

    Published: 16 Jul 2012
    4
    Medium

    CVE-2011-4291

    Last Modified: 11 Apr 2025

    Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.

    Published: 16 Jul 2012
    4
    Medium

    CVE-2011-4292

    Last Modified: 11 Apr 2025

    Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.

    Published: 16 Jul 2012
    6.5
    Medium

    CVE-2011-4295

    Last Modified: 11 Apr 2025

    The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.

    Published: 16 Jul 2012
    5.5
    Medium

    CVE-2011-4296

    Last Modified: 11 Apr 2025

    lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote authenticated users to modify course filters by leveraging this role.

    Published: 16 Jul 2012
    6.4
    Medium

    CVE-2011-4297

    Last Modified: 11 Apr 2025

    comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.

    Published: 16 Jul 2012
    5.5
    Medium

    CVE-2011-4285

    Last Modified: 11 Apr 2025

    The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.

    Published: 16 Jul 2012
    4.3
    Medium

    CVE-2011-4286

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka FLV) files and (2) YouTube videos.

    Published: 16 Jul 2012
    6.4
    Medium

    CVE-2011-4293

    Last Modified: 11 Apr 2025

    The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote attackers to bypass intended access restrictions and write to an operating-system temporary directory via unspecified vectors.

    Published: 16 Jul 2012
    5.8
    Medium

    CVE-2011-4294

    Last Modified: 11 Apr 2025

    The error-message functionality in Moodle 1.9.x before 1.9.13, 2.0.x before 2.0.4, and 2.1.x before 2.1.1 does not ensure that a continuation link refers to an http or https URL for the local Moodle instance, which might allow attackers to trick users into visiting arbitrary web sites via unspecified vectors.

    Published: 16 Jul 2012
    5
    Medium

    CVE-2011-4284

    Last Modified: 11 Apr 2025

    Moodle 2.0.x before 2.0.2 allows remote attackers to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context page.

    Published: 16 Jul 2012
    5
    Medium

    CVE-2012-6687

    Last Modified: 12 Apr 2025

    FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections.

    Published: 14 Jul 2012
    6.4
    Medium

    CVE-2012-2279

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 13 Jul 2012
    4.3
    Medium

    CVE-2012-0283

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.

    Published: 13 Jul 2012
    5
    Medium

    CVE-2012-2280

    Last Modified: 11 Apr 2025

    EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 do not properly use frames, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "Cross frame scripting vulnerability."

    Published: 13 Jul 2012
    4.3
    Medium

    CVE-2012-2278

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) Self-Service Console and (2) Security Console in EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Jul 2012
    9.3
    Critical

    CVE-2012-1661

    Last Modified: 11 Apr 2025

    ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.

    Published: 12 Jul 2012
    6.8
    Medium

    CVE-2012-2614

    Last Modified: 11 Apr 2025

    Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long string in a version attribute of an ispXCF element in an .xcf file.

    Published: 12 Jul 2012
    7.5
    High

    CVE-2012-2842

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to counter handling.

    Published: 12 Jul 2012
    9.3
    Critical

    CVE-2012-2844

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 20.0.1132.57 does not properly handle JavaScript code, which allows remote attackers to cause a denial of service (incorrect object access) or possibly have unspecified other impact via a crafted document.

    Published: 12 Jul 2012
    6.8
    Medium

    CVE-2012-3350

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Webmatic 3.1.1 allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header.

    Published: 12 Jul 2012
    4.3
    Medium

    CVE-2012-3997

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Sticky Notes before 0.2.27052012.5 allow remote attackers to inject arbitrary web script or HTML via the (1) paste_user or (2) paste_lang parameter to (a) list.php or (b) show.php.

    Published: 12 Jul 2012
    4.3
    Medium

    CVE-2012-3999

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/login.php in Sticky Notes 0.3.09062012.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 12 Jul 2012
    4.3
    Medium

    CVE-2012-4000

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject arbitrary web script or HTML via textinputs array parameters.

    Published: 12 Jul 2012
    4.3
    Medium

    CVE-2012-3382

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ProcessRequest function in mcs/class/System.Web/System.Web/HttpForbiddenHandler.cs in Mono 2.10.8 and earlier allows remote attackers to inject arbitrary web script or HTML via a file with a crafted name and a forbidden extension, which is not properly handled in an error message.

    Published: 12 Jul 2012
    7.5
    High

    CVE-2012-2843

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 20.0.1132.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to layout height tracking.

    Published: 12 Jul 2012
    6.8
    Medium

    CVE-2012-3377

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Ogg_DecodePacket function in the OGG demuxer (modules/demux/ogg.c) in VideoLAN VLC media player before 2.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted OGG file.

    Published: 12 Jul 2012
    7.5
    High

    CVE-2012-3998

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Sticky Notes before 0.2.27052012.5 allow remote attackers to execute arbitrary SQL commands via the (1) paste id in admin/modules/mod_pastes.php or (2) show.php, (3) user id to admin/modules/mod_users.php, (4) project to list.php, or (5) session id to show.php.

    Published: 12 Jul 2012
    5.5
    Medium

    CVE-2012-0215

    Last Modified: 11 Apr 2025

    model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field in the relation model, which allows remote authenticated users to modify the privileges of arbitrary users via a (1) create, (2) write, (3) delete, or (4) copy rpc call.

    Published: 12 Jul 2012
    6.5
    Medium

    CVE-2012-1037

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP code via a URL in the sub_type parameter.

    Published: 12 Jul 2012
    3.3
    Low

    CVE-2012-1174

    Last Modified: 11 Apr 2025

    The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows local users to delete arbitrary files via a symlink attack on unspecified files, related to "particular records related with user session."

    Published: 12 Jul 2012
    5
    Medium

    CVE-2012-2351

    Last Modified: 11 Apr 2025

    The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.

    Published: 12 Jul 2012
    6.8
    Medium

    CVE-2012-3362

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in eXtplorer 2.1 RC3 and earlier allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an adduser admin action.

    Published: 12 Jul 2012
    3.6
    Low

    CVE-2012-1620

    Last Modified: 11 Apr 2025

    slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which reveals the desktop and active windows.

    Published: 12 Jul 2012
    7.5
    High

    CVE-2012-3376

    Last Modified: 11 Apr 2025

    DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same BlockPool twice from a NodeName, which might allow remote clients to read arbitrary blocks, write to blocks to which they only have read access, and have other unspecified impacts.

    Published: 12 Jul 2012
    7.5
    High

    CVE-2012-3399

    Last Modified: 11 Apr 2025

    Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.

    Published: 12 Jul 2012
    5
    Medium

    CVE-2012-3996

    Last Modified: 11 Apr 2025

    TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (1) admin/include_calendar.php, (2) tiki-rss_error.php, or (3) tiki-watershed_service.php.

    Published: 12 Jul 2012
    9.8
    Critical

    CVE-2012-0911

    Last Modified: 11 Apr 2025

    TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted serialized object in the (1) cookieName to lib/banners/bannerlib.php; (2) printpages or (3) printstructures parameter to (a) tiki-print_multi_pages.php or (b) tiki-print_pages.php; or (4) sendpages, (5) sendstructures, or (6) sendarticles parameter to tiki-send_objects.php, which is not properly handled when processed by the unserialize function.

    Published: 12 Jul 2012
    7.5
    High

    CVE-2012-3881

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in RTG 0.7.4 and RTG2 0.9.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) 95.php, (2) view.php, or (3) rtg.php.

    Published: 12 Jul 2012
    4.3
    Medium

    CVE-2012-3805

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the getAllPassedParams function in system/functions.php in Kajona before 3.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) absender_name, (2) absender_email, or (3) absender_nachricht parameter to the content page; (4) comment_name, (5) comment_subject, or (6) comment_message parameter to the postacomment module; (7) module parameter to index.php; (8) action parameter to the admin login page; (9) pv or (10) pe parameter in a list action to the user module; (11) user_username, (12) user_email, (13) user_forename, (14) user_name, (15) user_street, (16) user_postal, (17) user_city, (18) user_tel, or (19) user_mobil parameter in a newUser action to the user module; (20) group_name or (21) group_desc parameter in a groupNew action to the user module; (22) name, (23) browsername, (24) seostring, (25) keywords, or (26) folder_id parameter in a newPage action to the pages module; (27) element_name or (28) element_cachetime parameter in a newElement action in the pages module; (29) aspect_name parameter in a newAspect action in the system module; (30) filemanager_name, (31) filemanager_path, (32) filemanager_upload_filter, or (33) filemanager_view_filter parameter in a NewRepo action to the filemanager module; or (34) archive_title or (35) archive_path parameter in a newArchive action to the downloads module. NOTE: some of these details are obtained from third party information.

    Published: 12 Jul 2012
    9
    Critical

    CVE-2012-3075

    Last Modified: 11 Apr 2025

    The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.

    Published: 12 Jul 2012
    9
    Critical

    CVE-2012-3076

    Last Modified: 11 Apr 2025

    The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Bug ID CSCth85804.

    Published: 12 Jul 2012
    8.3
    High

    CVE-2012-2486

    Last Modified: 11 Apr 2025

    The Cisco Discovery Protocol (CDP) implementation on Cisco TelePresence Multipoint Switch before 1.9.0, Cisco TelePresence Immersive Endpoint Devices before 1.9.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server before 1.8.1 allows remote attackers to execute arbitrary code by leveraging certain adjacency and sending a malformed CDP packet, aka Bug IDs CSCtz40953, CSCtz40947, CSCtz40965, and CSCtz40953.

    Published: 12 Jul 2012
    8.3
    High

    CVE-2012-3074

    Last Modified: 11 Apr 2025

    An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382.

    Published: 12 Jul 2012
    7.8
    High

    CVE-2012-3073

    Last Modified: 11 Apr 2025

    The IP implementation on Cisco TelePresence Multipoint Switch before 1.8.1, Cisco TelePresence Manager before 1.9.0, and Cisco TelePresence Recording Server 1.8 and earlier allows remote attackers to cause a denial of service (networking outage or process crash) via (1) malformed IP packets, (2) a high rate of TCP connection requests, or (3) a high rate of TCP connection terminations, aka Bug IDs CSCti21830, CSCti21851, CSCtj19100, CSCtj19086, CSCtj19078, CSCty11219, CSCty11299, CSCty11323, and CSCty11338.

    Published: 12 Jul 2012