PT-2006-2941 · Mambo+1 · Mambo+1
Published
2006-04-21
·
Updated
2024-02-14
·
CVE-2006-1957
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Mambo (affected versions not specified)
Joomla! (affected versions not specified)
Description
The issue allows remote attackers to cause a denial of service, potentially leading to disk consumption and web-server outage, by making multiple requests with different values of the
feed parameter to the rss.php file, which is related to the com rss option.Recommendations
For Mambo, restrict access to the
rss.php file to minimize the risk of exploitation.
For Joomla!, consider disabling the com rss option until a patch is available.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joomla!
Mambo