Vulnerabilities > Mambo Foundation > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-09-11 CVE-2008-7212 Permissions, Privileges, and Access Controls vulnerability in multiple products
MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php, which reveals the installation path in an error message.
network
low complexity
mambo-foundation brilaps CWE-264
5.0
2008-05-28 CVE-2008-2497 Code Injection vulnerability in Mambo-Foundation Mambo
CRLF injection vulnerability in Mambo before 4.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
network
low complexity
mambo-foundation CWE-94
5.0