First published: Wed Jul 25 2001(Updated: )
index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo Site Server | =3.0.4 | |
Mambo Site Server | =3.0.3 | |
Mambo Site Server | =3.0 | |
Mambo Site Server | =3.0.5 | |
Mambo Site Server | =3.0.1 | |
Mambo Site Server | =3.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1011 has a high severity rating due to its ability to allow remote attackers to gain administrative privileges.
To fix CVE-2001-1011, upgrade Mambo Site Server to version 3.0.6 or later.
CVE-2001-1011 affects Mambo Site Server versions 3.0.0 through 3.0.5.
Attackers exploiting CVE-2001-1011 can gain unauthorized administrator access, compromising site integrity.
CVE-2001-1011 has been identified in multiple deployments of Mambo Site Server, particularly those not updated past version 3.0.5.