Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.1.2010.2067
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2067-1)
Summary:The remote host is missing an update for the Debian 'mahara' package(s) announced via the DSA-2067-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'mahara' package(s) announced via the DSA-2067-1 advisory.

Vulnerability Insight:
Several vulnerabilities were discovered in mahara, an electronic portfolio, weblog, and resume builder. The following Common Vulnerabilities and Exposures project ids identify them:

CVE-2010-1667

Multiple pages performed insufficient input sanitising, making them vulnerable to cross-site scripting attacks.

CVE-2010-1668

Multiple forms lacked protection against cross-site request forgery attacks, therefore making them vulnerable.

CVE-2010-1670

Gregor Anzelj discovered that it was possible to accidentally configure an installation of mahara that allows access to another user's account without a password.

CVE-2010-2479

Certain Internet Explorer-specific cross-site scripting vulnerabilities were discovered in HTML Purifier, of which a copy is included in the mahara package.

For the stable distribution (lenny), the problems have been fixed in version 1.0.4-4+lenny6.

For the testing distribution (squeeze), the problems will be fixed soon.

For the unstable distribution (sid), the problems have been fixed in version 1.2.5.

We recommend that you upgrade your mahara packages.

Affected Software/OS:
'mahara' package(s) on Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-1667
BugTraq ID: 41319
http://www.securityfocus.com/bid/41319
http://secunia.com/advisories/40431
XForce ISS Database: mahara-multiple-unspecified-xss(59993)
https://exchange.xforce.ibmcloud.com/vulnerabilities/59993
Common Vulnerability Exposure (CVE) ID: CVE-2010-1668
XForce ISS Database: mahara-multiple-unspecified-csrf(59994)
https://exchange.xforce.ibmcloud.com/vulnerabilities/59994
Common Vulnerability Exposure (CVE) ID: CVE-2010-1670
Common Vulnerability Exposure (CVE) ID: CVE-2010-2479
39613
http://secunia.com/advisories/39613
40431
41259
http://www.securityfocus.com/bid/41259
http://htmlpurifier.org/news/2010/0531-4.1.1-released
http://repo.or.cz/w/htmlpurifier.git/commitdiff/18e538317a877a0509ae71a860429c41770da230
http://wiki.mahara.org/Release_Notes/1.0.15
http://wiki.mahara.org/Release_Notes/1.1.9
http://wiki.mahara.org/Release_Notes/1.2.5
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.