vendor:
Mambo Server
by:
SecurityFocus
7.5
CVSS
HIGH
Unauthorized Access
284
CWE
Product Name: Mambo Server
Affected Version From: Mambo Server version 4.5 Beta 1.0.3
Affected Version To: Other versions could be affected as well.
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2004
Mambo Server Unauthorized Access Vulnerability
It has been reported that Mambo Server may be prone to an unauthorized access vulnerability that may allow an attacker to modify a user and/or an administrator's information such as password, email, name etc, after supplying a legitimate user id.
Mitigation:
Ensure that all users have unique passwords and that they are changed regularly. Ensure that all users are assigned the minimum privileges necessary to perform their job.