Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.801889
Categoría:Web application abuses
Título:Mahara Multiple Remote Vulnerabilities
Resumen:Mahara is prone to multiple remote vulnerabilities.
Descripción:Summary:
Mahara is prone to multiple remote vulnerabilities.

Vulnerability Insight:
- An error in artefact/plans/viewtasks.json.php, artefact/blog/posts.json.php,
and blocktype/myfriends/myfriends.json.php when checking a user's permission can be exploited to access
restricted views.

- An error in view/newviewtoken.json.php, artefact/plans/tasks.json.php, and artefact/blog/view/index.json.php
when checking a user's permission can be exploited to edit restricted views.

- An error in admin/users/search.json.php due to the 'INSTITUTIONALADMIN' permission not being checked can be
exploited to search and suspend other users.

- The application allows users to perform certain actions via HTTP requests without performing any validity
checks to verify the requests. This can be exploited to create an arbitrary user with administrative
privileges if a logged-in administrative user visits a malicious web site.

- Input passed via certain email fields as a result of forum posts and view feedback notifications is not
properly sanitised in artefact/comment/lib.php and interaction/forum/lib.php before being used.

- Improper handling of an https URL in the wwwroot configuration setting, allows user-assisted remote attackers
to obtain credentials by sniffing the network at a time when an http URL is used for a login.

Vulnerability Impact:
Successful exploitation will allow attackers to execute arbitrary script
code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based
authentication credentials, disclose or modify sensitive information, or perform certain administrative actions
and bypass security restrictions.

Affected Software/OS:
Mahara version prior to 1.3.6.

Solution:
Upgrade to Mahara version 1.3.6 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2011-1402
BugTraq ID: 47798
http://www.securityfocus.com/bid/47798
Debian Security Information: DSA-2246 (Google Search)
http://www.debian.org/security/2011/dsa-2246
http://secunia.com/advisories/44433
XForce ISS Database: mahara-newviewtokenjson-sec-bypass(67396)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67396
XForce ISS Database: mahara-searchjson-sec-bypass(67397)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67397
Common Vulnerability Exposure (CVE) ID: CVE-2011-1403
XForce ISS Database: mahara-unspecified-csrf(67398)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67398
Common Vulnerability Exposure (CVE) ID: CVE-2011-1404
XForce ISS Database: mahara-viewtasksjson-sec-bypass(67395)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67395
Common Vulnerability Exposure (CVE) ID: CVE-2011-1405
XForce ISS Database: mahara-email-fields-xss(67399)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67399
Common Vulnerability Exposure (CVE) ID: CVE-2011-1406
XForce ISS Database: mahara-https-weak-security(67400)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67400
CopyrightCopyright (C) 2011 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.