Oval Definition:oval:org.mitre.oval:def:7296
Revision Date:2010-02-08Version:17
Title:DSA-1778 mahara -- insufficient input sanitization
Description:It was discovered that mahara, an electronic portfolio, weblog, and resume builder, is prone to cross-site scripting (XSS) attacks because of missing input sanitization of the introduction text field in user profiles and any text field in a user view. The oldstable distribution (etch) does not contain mahara.
Family:unixClass:patch
Status:ACCEPTEDReference(s):DSA-1778
Platform(s):Debian GNU/Linux 5.0
Product(s):mahara
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • mahara-apache2 is earlier than 1.0.4-4+lenny2
  • OR mahara is earlier than 1.0.4-4+lenny2
  • BACK