Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mahara mahara 1.2.3 vulnerabilities and exploits
(subscribe to this query)
516
VMScore
CVE-2011-0440
Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x prior to 1.2.7 and 1.3.x prior to 1.3.4 allows remote malicious users to hijack the authentication of arbitrary users for requests that delete blogs.
Mahara Mahara 1.2.0
Mahara Mahara 1.2.4
Mahara Mahara 1.2.3
Mahara Mahara 1.2.1
Mahara Mahara 1.2.2
Mahara Mahara 1.2.5
Mahara Mahara 1.2.6
Mahara Mahara 1.3.0
Mahara Mahara 1.3.2
Mahara Mahara 1.3.3
Mahara Mahara 1.3.1
445
VMScore
CVE-2014-1878
Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and previous versions, and Icinga prior to 1.8.6, 1.9 prior to 1.9.5, and 1.10 prior to 1.10.3 allows remote malicious users to cause a denial of service (segmentation fault) vi...
Nagios Nagios
Icinga Icinga 1.10.0
Icinga Icinga 1.8.0
Icinga Icinga 1.8.1
Nagios Nagios 4.0.0
Icinga Icinga 1.9.2
Icinga Icinga 1.9.3
Icinga Icinga 1.9.4
Icinga Icinga 1.9.0
Icinga Icinga 1.9.1
Icinga Icinga 1.8.4
Icinga Icinga
Icinga Icinga 1.10.1
Icinga Icinga 1.10.2
Icinga Icinga 1.8.2
Icinga Icinga 1.8.3
Nagios Nagios 4.0.2
445
VMScore
CVE-2012-2351
The default configuration of the auth/saml plugin in Mahara prior to 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.
Debian Debian Linux 6.0
Mahara Mahara 1.4
Mahara Mahara 1.3.3
Mahara Mahara 1.2.6
Mahara Mahara 1.2.0
Mahara Mahara 1.1.1
Mahara Mahara 1.1.0
Mahara Mahara 1.1.7
Mahara Mahara 1.1.8
Mahara Mahara 1.1
Mahara Mahara 1.0.9
Mahara Mahara 1.0.6
Mahara Mahara 1.0.14
Mahara Mahara 1.0.15
Mahara Mahara 0.9.1
Mahara Mahara 0.9.2
Mahara Mahara 1.3.0
Mahara Mahara 1.3.1
Mahara Mahara 1.2.2
Mahara Mahara 1.1.6
Mahara Mahara 1.0.0
Mahara Mahara 1.0.4
445
VMScore
CVE-2011-2772
The get_dataroot_image_path function in lib/file.php in Mahara prior to 1.4.1 does not properly validate uploaded image files, which allows remote malicious users to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.
Mahara Mahara 1.0.7
Mahara Mahara 1.1.0
Mahara Mahara 1.0.2
Mahara Mahara 1.0.0
Mahara Mahara 1.3.0
Mahara Mahara 1.2.0
Mahara Mahara 1.1.3
Mahara Mahara 1.2.4
Mahara Mahara 1.2.3
Mahara Mahara 1.1.2
Mahara Mahara 1.3.5
Mahara Mahara 1.0.6
Mahara Mahara 1.1.1
Mahara Mahara 0.9.2
Mahara Mahara 1.0.12
Mahara Mahara 1.0.10
Mahara Mahara 1.0.13
Mahara Mahara 1.1.6
Mahara Mahara 1.2.1
Mahara Mahara 0.9.0
Mahara Mahara 1.4
Mahara Mahara
383
VMScore
CVE-2011-2771
Multiple cross-site scripting (XSS) vulnerabilities in Mahara prior to 1.4.1 allow remote malicious users to inject arbitrary web script or HTML via vectors related to (1) URI attributes and (2) the External Feed component, as demonstrated by the guid element in an RSS feed.
Mahara Mahara 1.0.9
Mahara Mahara 1.1.2
Mahara Mahara 1.3.5
Mahara Mahara 1.0.6
Mahara Mahara 1.1.1
Mahara Mahara 0.9.2
Mahara Mahara 1.0.12
Mahara Mahara 1.3.0
Mahara Mahara 1.0.10
Mahara Mahara 1.0.13
Mahara Mahara 1.1.6
Mahara Mahara 1.2.0
Mahara Mahara 1.3.4
Mahara Mahara 1.0.5
Mahara Mahara 1.1.0
Mahara Mahara 1.0.4
Mahara Mahara 0.9.1
Mahara Mahara 1.2.6
Mahara Mahara 1.1.5
Mahara Mahara 1.1.9
Mahara Mahara 1.0.15
Mahara Mahara 1.1
383
VMScore
CVE-2011-1406
Mahara prior to 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote malicious users to obtain credentials by sniffing the network at a time when an http URL is used for a login.
Mahara Mahara 1.0.9
Mahara Mahara 1.1.2
Mahara Mahara 1.0.7
Mahara Mahara 1.1.0
Mahara Mahara 0.9.2
Mahara Mahara 1.0.12
Mahara Mahara 1.3.0
Mahara Mahara 1.1.3
Mahara Mahara 1.2.0
Mahara Mahara 1.0.5
Mahara Mahara 1.0.4
Mahara Mahara 1.0.3
Mahara Mahara 1.3.2
Mahara Mahara 1.1.5
Mahara Mahara 1.0.11
Mahara Mahara 1.0.15
Mahara Mahara 1.1.7
Mahara Mahara 1.3.3
Mahara Mahara 1.2.2
Mahara Mahara 1.2.5
Mahara Mahara 1.3.4
Mahara Mahara 1.0.6
383
VMScore
CVE-2011-0439
Cross-site scripting (XSS) vulnerability in Mahara 1.2.x prior to 1.2.7 and 1.3.x prior to 1.3.4 allows remote malicious users to inject arbitrary web script or HTML via the Pieforms select box.
Mahara Mahara 1.2.0
Mahara Mahara 1.2.3
Mahara Mahara 1.2.5
Mahara Mahara 1.2.1
Mahara Mahara 1.2.2
Mahara Mahara 1.2.6
Mahara Mahara 1.3.3
Mahara Mahara 1.2.4
Mahara Mahara 1.3.0
Mahara Mahara 1.3.2
Mahara Mahara 1.3.1
383
VMScore
CVE-2010-3871
Cross-site scripting (XSS) vulnerability in blocktype/groupviews/theme/raw/groupviews.tpl in Mahara prior to 1.3.3 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.
Mahara Mahara 1.0.9
Mahara Mahara 1.0.8
Mahara Mahara 1.1.0
Mahara Mahara 1.0.1
Mahara Mahara 0.9.2
Mahara Mahara 1.1.2
Mahara Mahara 1.1.1
Mahara Mahara 1.0.7
Mahara Mahara 1.0.2
Mahara Mahara 1.0.12
Mahara Mahara 1.3.0
Mahara Mahara 1.0.13
Mahara Mahara 1.1.6
Mahara Mahara 1.1.3
Mahara Mahara 1.2.0
Mahara Mahara 1.0.14
Mahara Mahara 1.2.1
Mahara Mahara 0.9.0
Mahara Mahara 1.2.3
Mahara Mahara 1.2.5
Mahara Mahara 1.0.6
Mahara Mahara 1.0.0
383
VMScore
CVE-2010-2479
Cross-site scripting (XSS) vulnerability in HTML Purifier prior to 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Htmlpurifier Htmlpurifier
Htmlpurifier Htmlpurifier 3.1.0
Htmlpurifier Htmlpurifier 2.1.3
Htmlpurifier Htmlpurifier 2.1.0
Htmlpurifier Htmlpurifier 1.4.1
Htmlpurifier Htmlpurifier 1.4.0
Htmlpurifier Htmlpurifier 1.3.2
Htmlpurifier Htmlpurifier 3.3.0
Htmlpurifier Htmlpurifier 3.2.0
Htmlpurifier Htmlpurifier 3.0.0
Htmlpurifier Htmlpurifier 2.1.5
Htmlpurifier Htmlpurifier 2.1.2
Htmlpurifier Htmlpurifier 2.1.1
Htmlpurifier Htmlpurifier 2.0.0
Htmlpurifier Htmlpurifier 1.6.1
Htmlpurifier Htmlpurifier 1.1.1
Htmlpurifier Htmlpurifier 1.1.0
Htmlpurifier Htmlpurifier 1.0.1
Htmlpurifier Htmlpurifier 1.0.0
Htmlpurifier Htmlpurifier 4.0.0
Htmlpurifier Htmlpurifier 3.1.1
Htmlpurifier Htmlpurifier 2.1.4
383
VMScore
CVE-2010-1667
Multiple cross-site scripting (XSS) vulnerabilities in Mahara prior to 1.0.15, 1.1.x prior to 1.1.9, and 1.2.x prior to 1.2.5 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Mahara Mahara 0.9.1
Mahara Mahara 0.9.0
Mahara Mahara 1.0.5
Mahara Mahara 1.0.6
Mahara Mahara
Mahara Mahara 1.0.1
Mahara Mahara 1.0.2
Mahara Mahara 1.0.10
Mahara Mahara 1.0.11
Mahara Mahara 0.9.2
Mahara Mahara 1.0.0
Mahara Mahara 1.0.7
Mahara Mahara 1.0.8
Mahara Mahara 1.0.3
Mahara Mahara 1.0.4
Mahara Mahara 1.0.12
Mahara Mahara 1.0.13
Mahara Mahara 1.1.0
Mahara Mahara 1.1.6
Mahara Mahara 1.1.5
Mahara Mahara 1.1.7
Mahara Mahara 1.1.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5324
path traversal
CVE-2024-4743
CVE-2024-5184
TCP
CVE-2024-27822
code injection
CVE-2024-28995
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »