First published: Sat Nov 24 2012(Updated: )
Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mahara | >=1.4.0<1.4.4 | |
Mahara | >=1.5.0<1.5.3 | |
Debian | =6.0 | |
Mahara | =1.1.4 | |
Mahara | =1.1.5 | |
Mahara | =1.4-rc1 | |
Mahara | =1.4-rc2 | |
Mahara | =1.4-rc3 | |
Mahara | =1.4-rc4 | |
Mahara | =1.4.0 | |
Mahara | =1.4.1 | |
Mahara | =1.4.2 | |
Mahara | =1.4.3 | |
Mahara | =1.5-rc1 | |
Mahara | =1.5-rc2 | |
Mahara | =1.5.0 | |
Mahara | =1.5.1 | |
Mahara | =1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2239 has a medium severity rating as it allows remote file reading through an XXE injection.
To fix CVE-2012-2239, upgrade Mahara to version 1.4.4 or later, or 1.5.3 or later.
CVE-2012-2239 affects Mahara versions 1.4.0 to 1.4.3 and 1.5.0 to 1.5.2.
Yes, CVE-2012-2239 can be exploited remotely by attackers to read arbitrary files.
CVE-2012-2239 is associated with an XML external entity (XXE) injection attack.