6.4
CVSSv2

CVE-2006-0871

Published: 24/02/2006 Updated: 07/03/2011
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote malicious users to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.

Vulnerable Product Search on Vulmon Subscribe to Product

mambo mambo 4.5.3h

Exploits

Mambo Multiple Vulnerabilities Vendor: Miro International Pty Ltd Product: Mambo Version: <= 453h Website: wwwmamboservercom BID: 16775 CVE: CVE-2006-0871 CVE-2006-1794 OSVDB: 23402 23503 23505 SECUNIA: 18935 PACKETSTORM: 44191 Description: Mambo is a popular Open Source Content Management System released under the GNU General ...