Lucene search

K
cveRedhatCVE-2011-4592
HistoryJul 20, 2012 - 10:40 a.m.

CVE-2011-4592

2012-07-2010:40:36
CWE-264
redhat
web.nvd.nist.gov
29
cve-2011-4592
moodle
cron
ip blocking
remote attackers
security issue

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

64.7%

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might allow remote attackers to bypass intended IP address restrictions by leveraging a configuration in which IP blocking was disabled to restore cron functionality.

Affected configurations

Nvd
Node
moodlemoodleMatch2.0.0
OR
moodlemoodleMatch2.0.1
OR
moodlemoodleMatch2.0.2
OR
moodlemoodleMatch2.0.3
OR
moodlemoodleMatch2.0.4
OR
moodlemoodleMatch2.0.5
Node
moodlemoodleMatch2.1.0
OR
moodlemoodleMatch2.1.1
OR
moodlemoodleMatch2.1.2
VendorProductVersionCPE
moodlemoodle2.0.3cpe:/a:moodle:moodle:2.0.3:::
moodlemoodle2.0.2cpe:/a:moodle:moodle:2.0.2:::
moodlemoodle2.0.5cpe:/a:moodle:moodle:2.0.5:::
moodlemoodle2.0.0cpe:/a:moodle:moodle:2.0.0:::
moodlemoodle2.0.1cpe:/a:moodle:moodle:2.0.1:::
moodlemoodle2.0.4cpe:/a:moodle:moodle:2.0.4:::

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.002

Percentile

64.7%