CVE-2009-3298
- EPSS 1.4%
- Veröffentlicht 03.11.2009 16:30:12
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote authenticated institution administrators to reset a site administrator password via unspecified vectors.
CVE-2009-3299
- EPSS 0.6%
- Veröffentlicht 03.11.2009 16:30:12
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the resume blocktype in Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2009-2170
- EPSS 0.26%
- Veröffentlicht 23.06.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.12 and 1.1 before 1.1.5 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
- EPSS 0.18%
- Veröffentlicht 23.06.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user's artefact.
CVE-2009-0664
- EPSS 0.44%
- Veröffentlicht 23.04.2009 17:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0.x before 1.0.11 and 1.1.x before 1.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the introduction field in a user profile or (2) an arbitrary text block in ...
CVE-2009-0660
- EPSS 0.47%
- Veröffentlicht 11.03.2009 14:19:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.10 and 1.1 before 1.1.2 allow remote attackers to inject arbitrary web script or HTML via a (1) profile and (2) blog, a different vulnerability than CVE-2009-0487.
CVE-2009-0487
- EPSS 0.29%
- Veröffentlicht 09.02.2009 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows remote attackers to inject arbitrary web script or HTML via a crafted forum post.
CVE-2008-0381
- EPSS 0.36%
- Veröffentlicht 22.01.2008 20:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files.