PT-2001-2160 · Mambo · Mambo Site Server
Published
2001-07-25
·
Updated
2017-10-10
·
CVE-2001-1011
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mambo Site Server versions 3.0.0 through 3.0.5
Description
The issue allows remote attackers to gain administrator privileges by manipulating the
PHPSESSID parameter and providing appropriate administrator information in other parameters. This is achieved through the index2.php file.Recommendations
For Mambo Site Server versions 3.0.0 through 3.0.5, consider restricting access to the
index2.php file until a fix is available. As a temporary workaround, avoid using the PHPSESSID parameter in the affected endpoint.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mambo Site Server