5
CVSSv2

CVE-2002-2247

Published: 31/12/2002 Updated: 29/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote malicious users to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.

Vulnerable Product Search on Vulmon Subscribe to Product

mambo mambo site server 4.0.11

Exploits

source: wwwsecurityfocuscom/bid/6376/info Mambo Site Server is a freely available, open source web content management tool It is written in PHP, and available for Unix, Linux, and Microsoft Windows operating systems It has been reported that Mambo enables a script by default that may reveal sensitive information The phpinfophp script ...