CVE-2008-2905
30.06.2008, 18:24
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
Vendor | Product | Version |
---|---|---|
mambo | mambo | 4.0.14 |
mambo | mambo | 4.5 |
mambo | mambo | 4.5.0.2 |
mambo | mambo | 4.5.1.3 |
mambo | mambo | 4.5.1_1.0.9:_1.0 |
mambo | mambo | 4.5.1_beta:_beta |
mambo | mambo | 4.5.1_beta2:_beta2 |
mambo | mambo | 4.5.1a:a |
mambo | mambo | 4.5.2 |
mambo | mambo | 4.5.2.1 |
mambo | mambo | 4.5.2.2 |
mambo | mambo | 4.5.2.3 |
mambo | mambo | 4.5.3h:h |
mambo | mambo | 4.5.4 |
mambo | mambo | 4.5_1.0.0:_1.0 |
mambo | mambo | 4.5_1.0.1:_1.0 |
mambo | mambo | 4.5_1.0.2:_1.0 |
mambo | mambo | 4.5_1.0.3_beta:_1.0 |
mambo | mambo | 4.5_1.0.9:_1.0 |
mambo | mambo | 4.6 |
mambo | mambo | 4.6.1 |
mambo | mambo | 4.6.2 |
mambo | mambo | 4.6.4 |
𝑥
= Vulnerable software versions
References