This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Summuary
CPE Namecpe:/a:mahara:mahara:1.0.9
Detail
VendorMaharaFirst view 2009-03-11
ProductMaharaLast view 2012-07-12
Version1.0.9TypeApplication
Edition 
Language 
Update 
 
CPE Productcpe:/a:mahara:mahara

Activity : Overall

Related : CVE

 DateAlertAccess VectorAccess ComplexityAuthentication
52012-07-12CVE-2012-2351NetworkLowNone Requ...
62011-11-14CVE-2011-4118NetworkMediumRequires ...
6.82011-11-14CVE-2011-2773NetworkMediumNone Requ...
52011-11-14CVE-2011-2772NetworkLowNone Requ...
4.32011-11-14CVE-2011-2771NetworkMediumNone Requ...
Hide | Show 11 More...
 DateAlertAccess VectorAccess ComplexityAuthentication
4.32011-05-13CVE-2011-1406NetworkMediumNone Requ...
3.52011-05-13CVE-2011-1405NetworkMediumRequires ...
42011-05-13CVE-2011-1404NetworkLowRequires ...
6.82011-05-13CVE-2011-1403NetworkMediumNone Requ...
6.52011-05-13CVE-2011-1402NetworkLowRequires ...
4.32010-11-09CVE-2010-3871NetworkMediumNone Requ...
4.32010-07-06CVE-2010-2479NetworkMediumNone Requ...
6.82010-07-06CVE-2010-1668NetworkMediumNone Requ...
4.32009-06-23CVE-2009-2170NetworkMediumNone Requ...
4.32009-04-23CVE-2009-0664NetworkMediumNone Requ...
4.32009-03-11CVE-2009-0660NetworkMediumNone Requ...

CWE : Common Weakness Enumeration

%idName
43% (7)CWE-79Failure to Preserve Web Page Structure ('Cross-site Scripting')
18% (3)CWE-352Cross-Site Request Forgery (CSRF)
18% (3)CWE-264Permissions, Privileges, and Access Controls
12% (2)CWE-16Configuration
6% (1)CWE-20Improper Input Validation

Open Source Vulnerability Database (OSVDB)

idDescription
77207Mahara MNet XMLRPC Jump Remote Privilege Escalation
76919Mahara admin/users/addtoinstitution.php User Institution Manipulation CSRF
76918Mahara Overly Large Image Handling Remote DoS
76917Mahara External Feed Block Unspecified XSS
73458Mahara wwwroot https URL Parsing Credential Disclosure
Hide | Show 12 More...
idDescription
73457Mahara HTML Email Message XSS
73456Mahara Multiple Script AJAX Call Parsing Information Disclosure
73455Mahara Admin User Addition CSRF
73454Mahara Multiple Script Access Restriction Bypass
69111Mahara blocktype/groupviews/theme/raw/groupviews.tpl Unspecified Parameter XSS
66060Mahara Multiple Unspecified CSRF
64113HTML Purifier Unspecified XSS
55276Mahara Unspecified XSS
53892Mahara User Views Unspecified Text Blocks XSS
53891Mahara Introduction User Profile Field XSS
52843Mahara Blog Functionality Unspecified XSS
52842Mahara Profile Functionality Unspecified XSS

OpenVAS Exploits

idDescription
2012-05-31Name : Debian Security Advisory DSA 2467-1 (mahara)
File : nvt/deb_2467_1.nasl
2012-02-11Name : Debian Security Advisory DSA 2334-1 (mahara)
File : nvt/deb_2334_1.nasl
2011-08-03Name : Debian Security Advisory DSA 2246-1 (mahara)
File : nvt/deb_2246_1.nasl
2011-05-23Name : Mahara Multiple Remote Vulnerabilities
File : nvt/gb_mahara_mult_vuln.nasl
2010-12-02Name : Fedora Update for moodle FEDORA-2010-13396
File : nvt/gb_fedora_2010_13396_moodle_fc14.nasl
Hide | Show 10 More...
idDescription
2010-11-09Name : Mahara 'groupviews.tpl' Cross Site Scripting Vulnerability
File : nvt/gb_mahara_44705.nasl
2010-08-24Name : Fedora Update for moodle FEDORA-2010-13250
File : nvt/gb_fedora_2010_13250_moodle_fc13.nasl
2010-08-24Name : Fedora Update for moodle FEDORA-2010-13254
File : nvt/gb_fedora_2010_13254_moodle_fc12.nasl
2010-07-05Name : Mahara Multiple Remote Vulnerabilities
File : nvt/gb_mahara_41319.nasl
2009-06-26Name : Mahara Cross-Site Scripting Vulnerability
File : nvt/secpod_mahara_xss_vuln.nasl
2009-06-05Name : Ubuntu USN-763-1 (xine-lib)
File : nvt/ubuntu_763_1.nasl
2009-04-28Name : Debian Security Advisory DSA 1778-1 (mahara)
File : nvt/deb_1778_1.nasl
2009-03-20Name : Debian Security Advisory DSA 1736-1 (mahara)
File : nvt/deb_1736_1.nasl
2009-03-13Name : Ubuntu USN-731-1 (apache2)
File : nvt/ubuntu_731_1.nasl
2009-03-13Name : Ubuntu USN-732-1 (dash)
File : nvt/ubuntu_732_1.nasl

Nessus® Vulnerability Scanner

idDescription
2012-05-10Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2467.nasl - Type : ACT_GATHER_INFO
2011-11-07Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2334.nasl - Type : ACT_GATHER_INFO
2011-06-10Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2246.nasl - Type : ACT_GATHER_INFO
2010-08-24Name : The remote Fedora host is missing a security update.
File : fedora_2010-13396.nasl - Type : ACT_GATHER_INFO
2010-08-23Name : The remote Fedora host is missing a security update.
File : fedora_2010-13250.nasl - Type : ACT_GATHER_INFO
Hide | Show 5 More...
idDescription
2010-08-23Name : The remote Fedora host is missing a security update.
File : fedora_2010-13254.nasl - Type : ACT_GATHER_INFO
2010-07-05Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2067.nasl - Type : ACT_GATHER_INFO
2009-06-24Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1822.nasl - Type : ACT_GATHER_INFO
2009-04-23Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1778.nasl - Type : ACT_GATHER_INFO
2009-03-11Name : The remote Debian host is missing a security-related update.
File : debian_DSA-1736.nasl - Type : ACT_GATHER_INFO