VulnerabilityModified
CVE-2002-2247
The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.
MEDIUM 5.0EPSS 2.57%
Does this matter?
Lower severity and a low EPSS score (2.57%). Track it; it rarely justifies an emergency change on its own.
Description
The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.57% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- mambo/mambo site server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-12/0111.html
- http://www.securityfocus.com/bid/6376Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10853
- http://archives.neohapsis.com/archives/bugtraq/2002-12/0111.html
- http://www.securityfocus.com/bid/6376Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10853
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.