CVE-2012-2239: Code Injection
Published Nov 24, 2012
·Updated
Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
Affected Software
18 affected components
Mahara Mahara=1.1.4
Mahara Mahara=1.1.5
Mahara Mahara=1.4-rc1
Mahara Mahara=1.4-rc2
Mahara Mahara=1.4-rc3
Mahara Mahara=1.4-rc4
Mahara Mahara=1.4.0
Mahara Mahara=1.4.1
Mahara Mahara=1.4.2
Mahara Mahara=1.4.3
Mahara Mahara=1.5-rc1
Mahara Mahara=1.5-rc2
Mahara Mahara=1.5.0
Mahara Mahara=1.5.1
Mahara Mahara=1.5.2
Mahara Mahara>=1.4.0<1.4.4
Mahara Mahara>=1.5.0<1.5.3
Debian Debian Linux=6.0
Remediation
Patch Available
Event History
Nov 24, 2012
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2239?
CVE-2012-2239 has a medium severity rating as it allows remote file reading through an XXE injection.
2
How do I fix CVE-2012-2239?
To fix CVE-2012-2239, upgrade Mahara to version 1.4.4 or later, or 1.5.3 or later.
3
What versions of Mahara are affected by CVE-2012-2239?
CVE-2012-2239 affects Mahara versions 1.4.0 to 1.4.3 and 1.5.0 to 1.5.2.
4
Can CVE-2012-2239 be exploited remotely?
Yes, CVE-2012-2239 can be exploited remotely by attackers to read arbitrary files.
5
What type of attack is CVE-2012-2239 associated with?
CVE-2012-2239 is associated with an XML external entity (XXE) injection attack.