Vulnerabilities > Configuration

DATE CVE VULNERABILITY TITLE RISK
2012-07-23 CVE-2012-3392 Configuration vulnerability in Moodle
mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass forum-subscription requirements by leveraging the student role and unsubscribing from all forums.
network
low complexity
moodle CWE-16
5.5
2012-07-17 CVE-2012-0797 Configuration vulnerability in Moodle
The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue using a server via a token.
network
low complexity
moodle CWE-16
5.5
2012-04-10 CVE-2012-0147 Configuration vulnerability in Microsoft Forefront Unified Access Gateway 2010
Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
network
low complexity
microsoft CWE-16
5.0
2011-11-22 CVE-2011-4506 Configuration vulnerability in Technicolor Tg585 Router and Tg585 Router Firmware
The UPnP IGD implementation on the Thomson (aka Technicolor) TG585 with firmware 7.x before 7.4.3.2 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
network
low complexity
technicolor CWE-16
7.5
2011-11-22 CVE-2011-4505 Configuration vulnerability in Alcatel products
The UPnP IGD implementation on SpeedTouch 5x6 devices with firmware before 6.2.29 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
network
low complexity
alcatel CWE-16
7.5
2011-11-22 CVE-2011-4504 Configuration vulnerability in multiple products
The UPnP IGD implementation in the Pseudo ICS UPnP software on the ZyXEL P-330W allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
network
low complexity
genmei-mori zyxel CWE-16
7.5
2011-11-22 CVE-2011-4503 Configuration vulnerability in multiple products
The UPnP IGD implementation in Broadcom Linux on the Sitecom WL-111 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
network
low complexity
broadcom sitecom CWE-16
7.5
2011-11-22 CVE-2011-4501 Configuration vulnerability in multiple products
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
network
low complexity
edimax canyon-tech sitecom sweex CWE-16
critical
10.0
2011-11-22 CVE-2011-4500 Configuration vulnerability in multiple products
The UPnP IGD implementation on the Cisco Linksys WRT54GX with firmware 2.00.05, when UPnP is enabled, configures the SOAP server to listen on the WAN port, which allows remote attackers to administer the firewall via SOAP requests.
network
low complexity
cisco linksys CWE-16
7.5
2011-11-22 CVE-2011-4499 Configuration vulnerability in multiple products
The UPnP IGD implementation in the Broadcom UPnP stack on the Cisco Linksys WRT54G with firmware before 4.30.5, WRT54GS v1 through v3 with firmware before 4.71.1, and WRT54GS v4 with firmware before 1.06.1 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP request to the WAN interface, related to an "external forwarding" vulnerability.
network
low complexity
cisco linksys CWE-16
7.5