PT-2001-2160 · Mambo · Mambo Site Server
Publicado
2001-07-25
·
Atualizado
2017-10-10
·
CVE-2001-1011
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mambo Site Server versions 3.0.0 through 3.0.5
Description
The issue allows remote attackers to gain administrator privileges by manipulating the
PHPSESSID parameter and providing appropriate administrator information in other parameters. This is achieved through the index2.php file.Recommendations
For Mambo Site Server versions 3.0.0 through 3.0.5, consider restricting access to the
index2.php file until a fix is available. As a temporary workaround, avoid using the PHPSESSID parameter in the affected endpoint.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mambo Site Server