2.6
CVE-2005-3738
- EPSS 7.52%
- Published 22.11.2005 11:03:00
- Last modified 03.04.2025 01:03:51
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.
Data is provided by the National Vulnerability Database (NVD)
Mambo ≫ Mambo Site Server Version4.0
Mambo ≫ Mambo Site Server Version4.0.10
Mambo ≫ Mambo Site Server Version4.0.11
Mambo ≫ Mambo Site Server Version4.0.12
Mambo ≫ Mambo Site Server Version4.0.12_beta
Mambo ≫ Mambo Site Server Version4.0.12_beta_2
Mambo ≫ Mambo Site Server Version4.0.12_rc1
Mambo ≫ Mambo Site Server Version4.0.12_rc2
Mambo ≫ Mambo Site Server Version4.0.12_rc3
Mambo ≫ Mambo Site Server Version4.0.14
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 7.52% | 0.91 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:P/A:N
|