Show filters
388 Total Results
Displaying 21-30 of 388
Sort by:
Attacker Value
Unknown
CVE-2017-1000135
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable as logged-in users can stay logged in after the institution they belong to is suspended.
0
Attacker Value
Unknown
CVE-2017-1000136
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.
0
Attacker Value
Unknown
CVE-2017-1000143
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users receiving watchlist notifications about pages they do not have access to anymore.
0
Attacker Value
Unknown
CVE-2017-1000134
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.
0
Attacker Value
Unknown
CVE-2017-1000139
Disclosure Date: November 03, 2017 (last updated November 26, 2024)
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.
0
Attacker Value
Unknown
CVE-2016-8734
Disclosure Date: October 16, 2017 (last updated November 08, 2023)
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an excessive amount of CPU resources or memory.
0
Attacker Value
Unknown
CVE-2017-14614
Disclosure Date: October 10, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the Visor GUI Console in GridGain before 1.7.16, 1.8.x before 1.8.12, 1.9.x before 1.9.7, and 8.x before 8.1.5 allows remote authenticated users to read arbitrary files on remote cluster nodes via a crafted path.
0
Attacker Value
Unknown
CVE-2015-5282
Disclosure Date: September 25, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Foreman 1.7.0 and after.
0
Attacker Value
Unknown
CVE-2015-9228
Disclosure Date: September 12, 2017 (last updated November 26, 2024)
In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.
0
Attacker Value
Unknown
CVE-2017-9506
Disclosure Date: August 23, 2017 (last updated November 26, 2024)
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).
0