Vulnerabilities > CVE-2013-2562 - Credentials Management vulnerability in Mambo-Foundation Mambo CMS 4.6.5
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
References
- http://packetstormsecurity.com/files/108462/mambocms465-permdosdisclose.txt
- http://packetstormsecurity.com/files/108462/mambocms465-permdosdisclose.txt
- http://seclists.org/oss-sec/2013/q1/689
- http://seclists.org/oss-sec/2013/q1/689
- http://www.vapid.dhs.org/advisories/mambo_cms_4.6.5.html
- http://www.vapid.dhs.org/advisories/mambo_cms_4.6.5.html