1
Candidate: CVE-2010-1617
4
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1617
6
user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not
7
properly check a role, which allows remote authenticated users to obtain
8
the full names of other users via the course profile page.
11
kees> MSA-10-0003 http://tracker.moodle.org/browse/MDL-21830
14
Discovered-by: Klaus Kirchner
18
upstream: http://cvs.moodle.org/moodle/user/view.php?r1=1.168.2.28&r2=1.168.2.29
19
upstream_moodle: released (1.9.8)
20
dapper_moodle: ignored (reached end-of-life)
21
hardy_moodle: ignored (reached end-of-life)
22
jaunty_moodle: ignored (reached end-of-life)
23
karmic_moodle: ignored (reached end-of-life)
24
lucid_moodle: ignored (reached end-of-life)
25
maverick_moodle: ignored (reached end-of-life)
26
natty_moodle: not-affected (1.9.9.dfsg2-2)
27
oneiric_moodle: not-affected (1.9.9.dfsg2-2)
28
precise_moodle: not-affected (1.9.9.dfsg2-2)
29
quantal_moodle: not-affected (1.9.9.dfsg2-2)
30
raring_moodle: not-affected (1.9.9.dfsg2-2)
31
saucy_moodle: not-affected (1.9.9.dfsg2-2)
32
devel_moodle: not-affected (1.9.9.dfsg2-2)