Mahara Versions Prior to 1.3.6 Multiple Remote Vulnerabilities
BID:47798
Info
Mahara Versions Prior to 1.3.6 Multiple Remote Vulnerabilities
| Bugtraq ID: | 47798 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1402 CVE-2011-1403 CVE-2011-1404 CVE-2011-1405 |
| Remote: | Yes |
| Local: | No |
| Published: | May 11 2011 12:00AM |
| Updated: | May 30 2011 04:31PM |
| Credit: | Bart van Delft and the vendor |
| Vulnerable: |
Mahara Mahara 1.3.5 Mahara Mahara 1.3.4 Mahara Mahara 1.3.3 Mahara Mahara 1.3.3 Mahara Mahara 1.2.5 Mahara Mahara 1.2.4 Mahara Mahara 1.2.3 Mahara Mahara 1.3.2 Mahara Mahara 1.3.1 Mahara Mahara 1.3.0 Mahara Mahara 1.2.6 Mahara Mahara 1.2.5 Mahara Mahara 1.2.2 Mahara Mahara 1.2.1 Mahara Mahara 1.2.0 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
Mahara Mahara 1.3.6 |
Discussion
Mahara Versions Prior to 1.3.6 Multiple Remote Vulnerabilities
Mahara is prone to multiple remote vulnerabilities, including:
1. Multiple security-bypass vulnerabilities
2. A cross-site request-forgery vulnerability
3. Multiple HTML-injection vulnerabilities
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, or perform certain administrative actions and bypass security restrictions. Other attacks are also possible.
Versions prior to Mahara 1.3.6 are affected.
Mahara is prone to multiple remote vulnerabilities, including:
1. Multiple security-bypass vulnerabilities
2. A cross-site request-forgery vulnerability
3. Multiple HTML-injection vulnerabilities
An attacker can exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose or modify sensitive information, or perform certain administrative actions and bypass security restrictions. Other attacks are also possible.
Versions prior to Mahara 1.3.6 are affected.
Exploit / POC
Mahara Versions Prior to 1.3.6 Multiple Remote Vulnerabilities
Attackers can exploit these issues through a browser. To exploit a cross-site request-forgery vulnerability, an attacker must entice an unsuspecting victim to view a malicious webpage.
Attackers can exploit these issues through a browser. To exploit a cross-site request-forgery vulnerability, an attacker must entice an unsuspecting victim to view a malicious webpage.
Solution / Fix
Mahara Versions Prior to 1.3.6 Multiple Remote Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Mahara Versions Prior to 1.3.6 Multiple Remote Vulnerabilities
References:
References:
- Mahara 1.3.6 Release Notes (Mahara)
- Mahara Homepage (Mahara)