The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.
References
Configurations
History
20 Nov 2024, 23:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2002-12/0111.html - | |
References | () http://www.securityfocus.com/bid/6376 - Exploit, Patch | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/10853 - |
Information
Published : 2002-12-31 05:00
Updated : 2024-11-20 23:43
NVD link : CVE-2002-2247
Mitre link : CVE-2002-2247
CVE.ORG link : CVE-2002-2247
JSON object : View
Products Affected
mambo
- mambo_site_server
CWE
CWE-16
Configuration