Vulnerabilities > Mambo > Mambo Site Server > Critical

DATE CVE VULNERABILITY TITLE RISK
2003-12-31 CVE-2003-1245 index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of a session cookie.
network
low complexity
mambo
critical
10.0
2002-12-31 CVE-2002-2290 Credentials Management vulnerability in Mambo Site Server 4.0.11
Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.
network
low complexity
mambo CWE-255
critical
10.0
2001-07-25 CVE-2001-1011 Unspecified vulnerability in Mambo Site Server
index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.
network
low complexity
mambo
critical
10.0