Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown
CVE-2011-1406
Disclosure Date: May 13, 2011 (last updated October 04, 2023)
Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.
0
Attacker Value
Unknown
CVE-2011-0439
Disclosure Date: March 28, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the Pieforms select box.
0
Attacker Value
Unknown
CVE-2011-0440
Disclosure Date: March 28, 2011 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.
0