Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
moodle moodle 2.0.1 vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2011-4287
admin/uploaduser_form.php in Moodle 2.0.x prior to 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote malicious users to obtain access by leveraging knowledge of the initial password of a new user.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
4
CVSSv2
CVE-2011-4291
Moodle 2.0.x prior to 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
4
CVSSv2
CVE-2011-4292
Moodle 2.0.x prior to 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted comments operations.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
4
CVSSv2
CVE-2011-4289
Moodle 2.0.x prior to 2.0.3 does not recognize the configuration setting that makes e-mail addresses visible only to course members, which allows remote authenticated users to obtain sensitive address information by reading a full profile page.
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
5
CVSSv2
CVE-2011-4279
Moodle 2.0.x prior to 2.0.2 does not use the forceloginforprofiles setting for course-profiles access control, which makes it easier for remote malicious users to obtain potentially sensitive information via vectors involving use of a search engine, as demonstrated by the search ...
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
6.8
CVSSv2
CVE-2011-4281
Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 2.0.x prior to 2.0.2 allow remote malicious users to hijack the authentication of arbitrary users for requests that mark the completion of (1) an activity or (2) a course.
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
4.3
CVSSv2
CVE-2011-4282
Multiple cross-site scripting (XSS) vulnerabilities in the course-tags functionality in tag/coursetags_more.php in Moodle 2.0.x prior to 2.0.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) sort or (2) show parameter.
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
5
CVSSv2
CVE-2011-4284
Moodle 2.0.x prior to 2.0.2 allows remote malicious users to obtain sensitive information from a myprofile (aka My profile) block by visiting a user-context page.
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
5.5
CVSSv2
CVE-2011-4285
The default configuration of Moodle 2.0.x prior to 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authenticated users to delete arbitrary courses by leveraging the teacher role.
Moodle Moodle 2.0.1
Moodle Moodle 2.0.0
6.4
CVSSv2
CVE-2011-4293
The theme implementation in Moodle 2.0.x prior to 2.0.4 and 2.1.x prior to 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScript content, which allows remote malicious users to bypass intended access restrictions and write to an operating-system temporar...
Moodle Moodle 2.0.2
Moodle Moodle 2.0.1
Moodle Moodle 2.0.3
Moodle Moodle 2.0.0
Moodle Moodle 2.1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4946
CVE-2024-30309
CVE-2024-4761
CVE-2024-30051
type confusion
memory leak
CVE-2024-30293
reflected XSS
CVE-2024-3126
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »