Moodle 1.6.1 and earlier allows remote attackers to obtain sensitive information via (1) help.php and (2) other unspecified vectors involving scheduled backups.
https://exchange.xforce.ibmcloud.com/vulnerabilities/28903
http://www.vupen.com/english/advisories/2006/3591
http://www.securityfocus.com/bid/19995