This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:mahara:mahara:1.1.0:alpha1 |
| Detail | |||
|---|---|---|---|
| Vendor | Mahara | First view | 2009-03-11 |
| Product | Mahara | Last view | 2012-07-12 |
| Version | 1.1.0 | Type | Application |
| Edition | |||
| Language | |||
| Update | alpha1 | ||
| CPE Product | cpe:/a:mahara:mahara | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 5 | 2012-07-12 | CVE-2012-2351 | Network | Low | None Requ... | |
| 6 | 2011-11-14 | CVE-2011-4118 | Network | Medium | Requires ... | |
| 6.8 | 2011-11-14 | CVE-2011-2773 | Network | Medium | None Requ... | |
| 5 | 2011-11-14 | CVE-2011-2772 | Network | Low | None Requ... | |
| 4.3 | 2011-11-14 | CVE-2011-2771 | Network | Medium | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 4.3 | 2011-05-13 | CVE-2011-1406 | Network | Medium | None Requ... | |
| 3.5 | 2011-05-13 | CVE-2011-1405 | Network | Medium | Requires ... | |
| 4 | 2011-05-13 | CVE-2011-1404 | Network | Low | Requires ... | |
| 6.8 | 2011-05-13 | CVE-2011-1403 | Network | Medium | None Requ... | |
| 6.5 | 2011-05-13 | CVE-2011-1402 | Network | Low | Requires ... | |
| 4.3 | 2010-11-09 | CVE-2010-3871 | Network | Medium | None Requ... | |
| 4.3 | 2010-07-06 | CVE-2010-2479 | Network | Medium | None Requ... | |
| 7.5 | 2010-07-06 | CVE-2010-1670 | Network | Low | None Requ... | |
| 7.5 | 2010-07-06 | CVE-2010-1669 | Network | Low | None Requ... | |
| 6.8 | 2010-07-06 | CVE-2010-1668 | Network | Medium | None Requ... | |
| 4.3 | 2010-07-06 | CVE-2010-1667 | Network | Medium | None Requ... | |
| 4.3 | 2009-11-03 | CVE-2009-3299 | Network | Medium | None Requ... | |
| 6.5 | 2009-11-03 | CVE-2009-3298 | Network | Low | Requires ... | |
| 4.3 | 2009-06-23 | CVE-2009-2170 | Network | Medium | None Requ... | |
| 4.3 | 2009-04-23 | CVE-2009-0664 | Network | Medium | None Requ... | |
| 4.3 | 2009-03-11 | CVE-2009-0660 | Network | Medium | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 42% (9) | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') |
| 19% (4) | CWE-264 | Permissions, Privileges, and Access Controls |
| 14% (3) | CWE-352 | Cross-Site Request Forgery (CSRF) |
| 9% (2) | CWE-16 | Configuration |
| 4% (1) | CWE-287 | Improper Authentication |
| % | id | Name |
|---|---|---|
| 4% (1) | CWE-89 | Improper Sanitization of Special Elements used in an SQL Command ('... |
| 4% (1) | CWE-20 | Improper Input Validation |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 77207 | Mahara MNet XMLRPC Jump Remote Privilege Escalation |
| 76919 | Mahara admin/users/addtoinstitution.php User Institution Manipulation CSRF |
| 76918 | Mahara Overly Large Image Handling Remote DoS |
| 76917 | Mahara External Feed Block Unspecified XSS |
| 73458 | Mahara wwwroot https URL Parsing Credential Disclosure |
| id | Description |
|---|---|
| 73457 | Mahara HTML Email Message XSS |
| 73456 | Mahara Multiple Script AJAX Call Parsing Information Disclosure |
| 73455 | Mahara Admin User Addition CSRF |
| 73454 | Mahara Multiple Script Access Restriction Bypass |
| 69111 | Mahara blocktype/groupviews/theme/raw/groupviews.tpl Unspecified Parameter XSS |
| 66062 | Mahara Single Sign-on Authentication Plugin Null Password Authentication Bypass |
| 66061 | Mahara Unspecified SQL Injection |
| 66060 | Mahara Multiple Unspecified CSRF |
| 66059 | Mahara Multiple Unspecified XSS |
| 64113 | HTML Purifier Unspecified XSS |
| 59584 | Mahara Site Admin Password Reset Remote Privilege Escalation |
| 59583 | Mahara Resume Blocktype XSS |
| 55276 | Mahara Unspecified XSS |
| 53892 | Mahara User Views Unspecified Text Blocks XSS |
| 53891 | Mahara Introduction User Profile Field XSS |
| 52843 | Mahara Blog Functionality Unspecified XSS |
| 52842 | Mahara Profile Functionality Unspecified XSS |







