globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-11-22T11:00:00
Updated: 2024-08-07T23:24:36.420Z
Reserved: 2005-11-22T00:00:00
Link: CVE-2005-3738
Vulnrichment
No data.
NVD
Status : Modified
Published: 2005-11-22T11:03:00.000
Modified: 2024-11-21T00:02:33.690
Link: CVE-2005-3738
Redhat
No data.