Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-2905


PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.


Published

2008-06-30T18:24:00.000

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mambo mambo 4.0.14 Yes
Application mambo mambo 4.5 Yes
Application mambo mambo 4.5.0.2 Yes
Application mambo mambo 4.5.1.3 Yes
Application mambo mambo 4.5.1_1.0.9 Yes
Application mambo mambo 4.5.1_beta Yes
Application mambo mambo 4.5.1_beta2 Yes
Application mambo mambo 4.5.1a Yes
Application mambo mambo 4.5.2 Yes
Application mambo mambo 4.5.2.1 Yes
Application mambo mambo 4.5.2.2 Yes
Application mambo mambo 4.5.2.3 Yes
Application mambo mambo 4.5.3h Yes
Application mambo mambo 4.5.4 Yes
Application mambo mambo 4.5_1.0.0 Yes
Application mambo mambo 4.5_1.0.1 Yes
Application mambo mambo 4.5_1.0.2 Yes
Application mambo mambo 4.5_1.0.3_beta Yes
Application mambo mambo 4.5_1.0.9 Yes
Application mambo mambo 4.6 Yes
Application mambo mambo 4.6.1 Yes
Application mambo mambo 4.6.2 Yes
Application mambo mambo 4.6.4 Yes

References