5
CVSSv2

CVE-2002-2288

Published: 31/12/2002 Updated: 29/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Mambo Site Server 4.0.11 allows remote malicious users to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

mambo site server 4.0.11

Exploits

source: wwwsecurityfocuscom/bid/6387/info A vulnerability has been discovered in Mambo Site Server Requesting the 'indexphp' script with an invalid parameter will cause an error page to be generated containing the path of the Mambo script Information obtained by exploiting this issue may aid an attacker in launching further attacks ag ...