Mambo-foundation

Mambo Cms

5 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Published 12.02.2020 20:15:13
  • Last modified 21.11.2024 01:28:24

Mambo CMS through 4.6.5 has multiple XSS.

Exploit
  • EPSS 0.26%
  • Published 15.02.2019 21:29:00
  • Last modified 21.11.2024 01:51:57

A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.

Exploit
  • EPSS 0.07%
  • Published 09.06.2014 19:55:09
  • Last modified 12.04.2025 10:46:40

Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.

Exploit
  • EPSS 0.06%
  • Published 09.06.2014 19:55:09
  • Last modified 12.04.2025 10:46:40

Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.

Exploit
  • EPSS 0.54%
  • Published 09.06.2014 19:55:09
  • Last modified 12.04.2025 10:46:40

Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.