Vulnerabilities > CVE-2003-1245
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nessus
exploit available
Summary
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Mambo Site Server 4.0.12 RC2 Cookie Validation Vulnerability. CVE-2003-1245. Webapps exploit for php platform |
id | EDB-ID:22281 |
last seen | 2016-02-02 |
modified | 2003-02-24 |
published | 2003-02-24 |
reporter | Simen Bergo |
source | https://www.exploit-db.com/download/22281/ |
title | Mambo Site Server 4.0.12 RC2 Cookie Validation Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | MAMBO.NASL |
description | The remote installation of Mambo Site Server improperly validates the cookies that are sent back by the user. As a result, a user may impersonate the administrator by using the MD5 value of a received cookie and thereby gain administrative control of the affected application. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11361 |
published | 2003-03-12 |
reporter | This script is Copyright (C) 2003-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11361 |
title | Mambo Site Server MD5 Hash Session ID Privilege Escalation |
code |
|