Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

CVE Kennung:CVE-2011-1404
Beschreibung:Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.
Test Kennungen: 1.3.6.1.4.1.25623.1.0.69743  
Querverweise: Common Vulnerability Exposure (CVE) ID: CVE-2011-1404
BugTraq ID: 47798
http://www.securityfocus.com/bid/47798
Debian Security Information: DSA-2246 (Google Search)
http://www.debian.org/security/2011/dsa-2246
http://secunia.com/advisories/44433
XForce ISS Database: mahara-viewtasksjson-sec-bypass(67395)
https://exchange.xforce.ibmcloud.com/vulnerabilities/67395




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.