Secunia Logo
 
CVE Reference: CVE-2005-3738
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-3738

Description:
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.

CVE Status:
Candidate

References:

ST
  1015258

SAID
  Secunia Advisory: SA17622

FULLDISC
  http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0520.html

CONFIRM
  http://forum.mamboserver.com/showthread.php?t=66154

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/427196/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/426942/100/0/threaded
  http://www.securityfocus.com/archive/1/417215

BID
  15461


Return to the previous page.