Candidate: CVE-2009-0664 PublicDate: 2009-04-23 17:30:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0664 Description: Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0.x before 1.0.11 and 1.1.x before 1.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the introduction field in a user profile or (2) an arbitrary text block in a user view. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_mahara: upstream_mahara: released (1.0.11, 1.1.3) dapper_mahara: DNE hardy_mahara: DNE intrepid_mahara: needed (reached end-of-life) jaunty_mahara: released (1.0.9-2ubuntu0.3) karmic_mahara: not-affected (1.1.5-1ubuntu0.1) devel_mahara: not-affected (1.2.0-2)