CVE-2005-3738
45Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 3.6%
from disclosure to weapon0 days
Published on NVDNov 22
1st PoCNov 22
VulnCheckNov 22
exploitation probability
3.6%top 12% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/1337⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0520.htmlhttp://forum.mamboserver.com/showthread.php?t=66154http://secunia.com/advisories/17622http://securitytracker.com/id?1015258http://www.securityfocus.com/archive/1/417215http://www.securityfocus.com/archive/1/426942/100/0/threadedhttp://www.securityfocus.com/archive/1/427196/100/0/threadedhttp://www.securityfocus.com/bid/15461http://www.vupen.com/english/advisories/2005/2473