Vulnerabilities > Mambo Foundation > Mambo CMS > Low

DATE CVE VULNERABILITY TITLE RISK
2014-06-09 CVE-2013-2562 Credentials Management vulnerability in Mambo-Foundation Mambo CMS 4.6.5
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.
local
low complexity
mambo-foundation CWE-255
2.1
2014-06-09 CVE-2013-2563 Permissions, Privileges, and Access Controls vulnerability in Mambo-Foundation Mambo CMS 4.6.5
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.
local
low complexity
mambo-foundation CWE-264
2.1