Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qg6h-2v97-496v

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.

globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.

EPSS

Процентиль: 90%
0.05487
Низкий

Связанные уязвимости

nvd
около 20 лет назад

globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.

EPSS

Процентиль: 90%
0.05487
Низкий