Логотип exploitDog
bind:CVE-2011-1404
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2011-1404

Количество 4

Количество 4

ubuntu логотип

CVE-2011-1404

больше 14 лет назад

Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2011-1404

больше 14 лет назад

Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2011-1404

больше 14 лет назад

Mahara before 1.3.6 does not properly restrict the data in responses t ...

CVSS2: 4
EPSS: Низкий
github логотип

GHSA-fjwm-vprq-674q

больше 3 лет назад

Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2011-1404

Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

CVSS2: 4
1%
Низкий
больше 14 лет назад
nvd логотип
CVE-2011-1404

Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

CVSS2: 4
1%
Низкий
больше 14 лет назад
debian логотип
CVE-2011-1404

Mahara before 1.3.6 does not properly restrict the data in responses t ...

CVSS2: 4
1%
Низкий
больше 14 лет назад
github логотип
GHSA-fjwm-vprq-674q

Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу