CVE-2002-2288
MEDIUM 5.0EPSS 2.0%
Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 2.01% chance of exploitation in the next 30 days, 80th percentile
- Published
- 2007-10-18
- Updated
- 2024-08-08