CVE-2012-2244

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav.  NOTE: this can be exploited without authentication by leveraging CVE-2012-2243.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
debianCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
VendorProductVersion
maharamahara
1.4:rc1
maharamahara
1.4:rc2
maharamahara
1.4:rc3
maharamahara
1.4:rc4
maharamahara
1.4.0
maharamahara
1.4.1
maharamahara
1.4.2
maharamahara
1.4.3
maharamahara
1.5:rc1
maharamahara
1.5:rc2
maharamahara
1.5.0
maharamahara
1.5.1
maharamahara
1.5.2
maharamahara
1.5.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mahara
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
not-affected
raring
not-affected
quantal
ignored
precise
ignored
oneiric
ignored
lucid
ignored
hardy
dne
Common Weakness Enumeration