Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: debian
Published: 2012-11-24T20:00:00
Updated: 2024-08-06T19:26:08.975Z
Reserved: 2012-04-16T00:00:00
Link: CVE-2012-2239
Vulnrichment
No data.
NVD
Status : Modified
Published: 2012-11-24T20:55:02.087
Modified: 2024-11-21T01:38:45.143
Link: CVE-2012-2239
Redhat
No data.