VendorsMambo-Foundationmambo_cms4.6.5
Vulnerabilities

Mambo-Foundation Mambo CMS 4.6.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2013-2565
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
Published 2019-02-15 · Modified
5.3EPSS 0.016
CVE-2013-2564
Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.
Published 2014-06-09 · Modified
5.0EPSS 0.025
CVE-2013-2562
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.
Published 2014-06-09 · Modified
2.1EPSS 0.005
CVE-2013-2563
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.
Published 2014-06-09 · Modified
2.1EPSS 0.005