Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authentication by leveraging CVE-2012-2243.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mahara 权限许可和访问控制漏洞
Vulnerability Description
Catalyst Mahara是新西兰Catalyst IT公司的一套社交网络系统。该系统包含博客、履历表生成器、文件管理器等。 Mahara 1.4.5之前的1.4.x版本以及1.5.4之前的 1.5.x版本中存在漏洞。通过修改到clamav的路径,具有认证的管理员权限的远程攻击者可利用该漏洞执行任意程序。
CVSS Information
N/A
Vulnerability Type
N/A