Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2013-2565

Disclosure Date: February 15, 2019 (last updated November 27, 2024)
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
0
Attacker Value
Unknown

CVE-2013-2563

Disclosure Date: June 09, 2014 (last updated October 05, 2023)
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.
0
Attacker Value
Unknown

CVE-2013-2564

Disclosure Date: June 09, 2014 (last updated October 05, 2023)
Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.
0
Attacker Value
Unknown

CVE-2013-2562

Disclosure Date: June 09, 2014 (last updated October 05, 2023)
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-3754

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
Mambo 4.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/sef.php and certain other files.
0
Attacker Value
Unknown

CVE-2008-3712

Disclosure Date: August 19, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php and the (2) mosConfig_sitename parameter to administrator/popups/index3pop.php.
0