Vulnerabilities (CVE)

Filtered by vendor Mambo-foundation Subscribe
Filtered by product Mambo Cms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-2562 1 Mambo-foundation 1 Mambo Cms 2014-06-24 2.1 LOW N/A
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.
CVE-2013-2563 1 Mambo-foundation 1 Mambo Cms 2014-06-24 2.1 LOW N/A
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.
CVE-2013-2564 1 Mambo-foundation 1 Mambo Cms 2014-06-24 5.0 MEDIUM N/A
Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.