RSS   Vulnerabilities for 'Mambo cms'   RSS

2019-02-15
 
CVE-2013-2565

CWE-22
 

 
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.

 
2014-06-09
 
CVE-2013-2564

CWE-399
 

 
Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.

 
 
CVE-2013-2563

CWE-264
 

 
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.

 
 
CVE-2013-2562

CWE-255
 

 
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.

 

 >>> Vendor: Mambo-foundation 3 Products
Mambo
Com musica
Mambo cms


Copyright 2024, cxsecurity.com

 

Back to Top