Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-11-24 12:55
Updated : 2013-02-07 20:50
NVD link : CVE-2012-2239
Mitre link : CVE-2012-2239
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
mahara
- mahara