oval:org.mitre.oval:def:11886

Definition Id: oval:org.mitre.oval:def:11886
 
Oval ID: oval:org.mitre.oval:def:11886
Title: DSA-2067 mahara -- several vulnerabilities
Description: Several vulnerabilities were discovered in mahara, an electronic portfolio, weblog, and resume builder. The following Common Vulnerabilities and Exposures project ids identify them: Multiple pages performed insufficient input sanitising, making them vulnerable to cross-site scripting attacks. Multiple forms lacked protection against cross-site request forgery attacks, therefore making them vulnerable. Gregor Anzelj discovered that it was possible to accidentally configure an installation of mahara that allows access to another user's account without a password. Certain Internet Explorer-specific cross-site scripting vulnerabilities were discovered in HTML Purifier, of which a copy is included in the mahara package.
Family: unix Class: patch
Reference(s): DSA-2067
CVE-2010-1667
CVE-2010-1668
CVE-2010-1670
CVE-2010-2479
Version: 5
Platform(s): Debian GNU/Linux 5.0
Product(s): mahara
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:6513
 
Oval ID: oval:org.mitre.oval:def:6513
Title: Debian GNU/Linux 5.0 is installed
Description: Debian GNU/Linux 5.0 (lenny) is installed
Family: unix Class: inventory
Reference(s): cpe:/o:debian:debian_gnu/linux:5.0
Version: 7
Platform(s): Debian GNU/Linux 5.0
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:11886