CVE-2011-4290
- EPSS 0.3%
- Veröffentlicht 16.07.2012 10:28:36
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in lib/weblib.php in Moodle 1.9.x before 1.9.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to URL encoding.
- EPSS 0.46%
- Veröffentlicht 16.07.2012 10:28:36
- Zuletzt bearbeitet 11.04.2025 00:51:21
Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.
- EPSS 0.57%
- Veröffentlicht 16.07.2012 10:28:36
- Zuletzt bearbeitet 11.04.2025 00:51:21
Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.
- EPSS 0.2%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
The chat functionality in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote authenticated users to discover the name of any user via a beep operation.
- EPSS 0.46%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
message/refresh.php in Moodle 1.9.x before 1.9.14 allows remote authenticated users to cause a denial of service (infinite request loop) via a URL that specifies a zero wait time for message refreshing.
CVE-2011-4306
- EPSS 0.3%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in course/editsection.html in Moodle 1.9.x before 1.9.14 allows remote authenticated users to inject arbitrary web script or HTML via crafted data.
CVE-2011-4307
- EPSS 0.3%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in mod/wiki/lang/en/wiki.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the section parameter.
- EPSS 0.27%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod/forum/user.php in Moodle 1.9.x before 1.9.14, 2.0.x before 2.0.5, and 2.1.x before 2.1.2 allows remote authenticated users to discover the names of other users via unspecified vectors.
- EPSS 0.21%
- Veröffentlicht 11.07.2012 10:26:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by leveraging the guest role and making a direct request to a URL.
CVE-2011-4298
- EPSS 0.13%
- Veröffentlicht 11.07.2012 10:26:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site request forgery (CSRF) vulnerabilities in mod/wiki/ components in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allow remote attackers to hijack the authentication of arbitrary users for requests that modify wiki data.