2.6

CVE-2005-3738

Exploit

globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.

Data is provided by the National Vulnerability Database (NVD)
MamboMambo Site Server Version4.0
MamboMambo Site Server Version4.0.10
MamboMambo Site Server Version4.0.11
MamboMambo Site Server Version4.0.12
MamboMambo Site Server Version4.0.12_beta
MamboMambo Site Server Version4.0.12_beta_2
MamboMambo Site Server Version4.0.12_rc1
MamboMambo Site Server Version4.0.12_rc2
MamboMambo Site Server Version4.0.12_rc3
MamboMambo Site Server Version4.0.14
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 7.52% 0.91
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N