Mahara Multiple Remote Vulnerabilities
BID:56713
Info
Mahara Multiple Remote Vulnerabilities
| Bugtraq ID: | 56713 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-2244 CVE-2012-2246 CVE-2012-6037 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 27 2012 12:00AM |
| Updated: | Dec 28 2012 08:30AM |
| Credit: | Mike Haworth, Ajay Singh Negi |
| Vulnerable: |
Mahara Mahara 1.4.1 Mahara Mahara 1.4 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
Mahara Multiple Remote Vulnerabilities
Mahara is prone to the following multiple vulnerabilities:
1. Remote code execution vulnerability (CVE-2012-2244)
2. Clickjacking vulnerability (CVE-2012-2246)
3. Multiple cross-site scripting vulnerabilities (CVE-2012-6037)
Exploiting these issues may allow an attacker to compromise the application, execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, control how the site is rendered to the user, or perform unauthorized actions on behalf of the user. Other attacks are also possible.
Mahara 1.4.x versions prior to 1.4.5 and 1.5.x versions prior to 1.5.4 are affected.
Mahara is prone to the following multiple vulnerabilities:
1. Remote code execution vulnerability (CVE-2012-2244)
2. Clickjacking vulnerability (CVE-2012-2246)
3. Multiple cross-site scripting vulnerabilities (CVE-2012-6037)
Exploiting these issues may allow an attacker to compromise the application, execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, control how the site is rendered to the user, or perform unauthorized actions on behalf of the user. Other attacks are also possible.
Mahara 1.4.x versions prior to 1.4.5 and 1.5.x versions prior to 1.5.4 are affected.
Exploit / POC
Mahara Multiple Remote Vulnerabilities
An attacker can use a web browser to exploit these issues. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to visit a crafted site.
An attacker can use a web browser to exploit these issues. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting user to visit a crafted site.
Solution / Fix
Mahara Multiple Remote Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.