PT-2007-1478 · Mambo · Mambo
Publicado
2007-05-09
·
Atualizado
2008-09-05
·
CVE-2006-7202
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Mambo version 4.6.1
Description
The issue concerns the
dofreePDF function in includes/pdf.php, which fails to properly check access rights for database content. This allows remote attackers to read certain content via unspecified vectors.Recommendations
For Mambo version 4.6.1, consider restricting access to the
dofreePDF function in includes/pdf.php until a proper fix is available. Additionally, review and tighten database access rights to minimize potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mambo