Vulnerabilities > Mambo > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2002-12-31 | CVE-2002-2247 | Configuration vulnerability in Mambo Site Server 4.0.11 The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function. | 5.0 |
2002-12-31 | CVE-2002-1662 | HTML Injection vulnerability in Mambo Site Server 4.0.11 Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.11 allow remote attackers to execute arbitrary script on other clients via (1) search.php and (2) the "Your name" field during account registration. network mambo | 6.8 |