- EPSS 0.58%
- Veröffentlicht 13.05.2011 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch....
CVE-2011-1405
- EPSS 0.29%
- Veröffentlicht 13.05.2011 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors associated with HTML e-mail messages, related to artefact/comment/lib.php and interaction/forum/lib.p...
CVE-2011-1406
- EPSS 0.28%
- Veröffentlicht 13.05.2011 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.
CVE-2011-0439
- EPSS 0.44%
- Veröffentlicht 28.03.2011 16:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the Pieforms select box.
CVE-2011-0440
- EPSS 0.3%
- Veröffentlicht 28.03.2011 16:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.
CVE-2010-3871
- EPSS 0.29%
- Veröffentlicht 09.11.2010 21:00:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in blocktype/groupviews/theme/raw/groupviews.tpl in Mahara before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from th...
CVE-2010-1667
- EPSS 0.41%
- Veröffentlicht 06.07.2010 17:17:14
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2010-1668
- EPSS 0.3%
- Veröffentlicht 06.07.2010 17:17:14
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site request forgery (CSRF) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVE-2010-1669
- EPSS 0.46%
- Veröffentlicht 06.07.2010 17:17:14
- Zuletzt bearbeitet 29.04.2026 01:13:23
SQL injection vulnerability in Mahara 1.1.x before 1.1.9 and 1.2.x before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2010-1670
- EPSS 0.44%
- Veröffentlicht 06.07.2010 17:17:14
- Zuletzt bearbeitet 29.04.2026 01:13:23
Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, which allows remote attackers to bypass authenticat...