📦

mambo_cms

Vendor: mambo-foundation

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 11 Total Indexed
Avg. EPSS 0.24% Exploit Prob.
Latest CVE CVE-2011-2499 Feb 12

Security Vulnerability Index

Page 1 / 2
6.1 CVSS

Mambo CMS through 4.6.5 has multiple XSS.

EPSS: 0.24%
5.3 CVSS

A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.

EPSS: 0.26%
5.0 CVSS

Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.

EPSS: 0.54%
2.1 CVSS

Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.

EPSS: 0.06%
2.1 CVSS

Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.

EPSS: 0.07%