Search: "mahara"

118 CVEs found

CVE-2008-0381
4.3 MEDIUM

Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files.

Published: 2008-01-22
Products: 1
Vendors:
mahara
CVE-2008-4796
10.0 HIGH

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other pr...

Published: 2008-10-30
Products: 5
Vendors:
snoopy_project nagios debian wordpress
CVE-2008-5619
10.0 HIGH

html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attacke...

Published: 2008-12-17
Products: 2
Vendors:
roundcube
CVE-2009-0487
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows remote attackers to inject arbitrary web script or HTML via a crafted forum post.

Published: 2009-02-09
Products: 12
Vendors:
mahara
CVE-2009-0660
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.10 and 1.1 before 1.1.2 allow remote attackers to inject arbitrary web script or HTML via a (1) profile and (2) blog, a dif...

Published: 2009-03-11
Products: 21
Vendors:
mahara
CVE-2009-0664
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0.x before 1.0.11 and 1.1.x before 1.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the introduction field in...

Published: 2009-04-23
Products: 22
Vendors:
mahara
CVE-2009-2170
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.12 and 1.1 before 1.1.5 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

Published: 2009-06-23
Products: 27
Vendors:
mahara
CVE-2009-2171
4.0 MEDIUM

Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user's artefact.

Published: 2009-06-23
Products: 5
Vendors:
mahara
CVE-2009-3298
6.5 MEDIUM

Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote authenticated institution administrators to reset a site administrator password via unspecified vectors.

Published: 2009-11-03
Products: 28
Vendors:
mahara
CVE-2009-3299
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in the resume blocktype in Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors...

Published: 2009-11-03
Products: 21
Vendors:
mahara

SQL injection vulnerability in lib/user.php in mahara 1.0.4 allows remote attackers to execute arbitrary SQL commands via a username.

Published: 2010-04-07
Products: 1
Vendors:
mahara
CVE-2010-1667
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified ve...

Published: 2010-07-06
Products: 49
Vendors:
mahara
CVE-2010-1668
6.8 MEDIUM

Multiple cross-site request forgery (CSRF) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to hijack the authentication of unspecified victim...

Published: 2010-07-06
Products: 49
Vendors:
mahara

SQL injection vulnerability in Mahara 1.1.x before 1.1.9 and 1.2.x before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Published: 2010-07-06
Products: 31
Vendors:
mahara

Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, w...

Published: 2010-07-06
Products: 49
Vendors:
mahara
CVE-2010-2479
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote attackers to inject arbitrary web scr...

Published: 2010-07-06
Products: 127
Vendors:
mahara htmlpurifier
CVE-2010-3871
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in blocktype/groupviews/theme/raw/groupviews.tpl in Mahara before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors....

Published: 2010-11-09
Products: 62
Vendors:
mahara
CVE-2011-0439
4.3 MEDIUM

Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the Pieforms select box.

Published: 2011-03-28
Products: 24
Vendors:
mahara
CVE-2011-0440
5.8 MEDIUM

Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blo...

Published: 2011-03-28
Products: 24
Vendors:
mahara
CVE-2011-1402
6.5 MEDIUM

Mahara before 1.3.6 allows remote authenticated users to bypass intended access restrictions, and suspend a user account, edit a view, visit a view, edit a plan artefact, read a plans block, read a pl...

Published: 2011-05-13
Products: 65
Vendors:
mahara