CVE-2005-3738
LOW 2.6EPSS 3.6%
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.
- CVSS v2.0
- 2.6 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N - EPSS
- 3.56% chance of exploitation in the next 30 days, 89th percentile
- Published
- 2005-11-22
- Updated
- 2024-08-07
Proof-of-concept exploits (3)
- http://www.securityfocus.com/archive/1/426942/100/0/threaded
- http://www.securityfocus.com/archive/1/427196/100/0/threaded
- http://www.securityfocus.com/archive/1/417215