CVE-2002-2290: Critical severity mambo mambo site server vulnerability
Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Change the default credentials installed as username 'admin' and password 'admin' to a unique administrator username and a strong, non-default password. If the application supports it, disable or remove the built-in 'admin' account.
Mambo Site Server 4.0.11 default admin username/password = do not use username 'admin' with password 'admin'; set a unique admin username and a strong password - Operational
Audit all Mambo Site Server 4.0.11 deployments for accounts using username/password 'admin'. Rotate any credentials that are still 'admin'/'admin' or that may have been exposed and review access logs for potential unauthorized access.
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2290?
CVE-2002-2290 has a high severity level due to the ease of remote exploitation of default credentials.
How do I fix CVE-2002-2290?
To fix CVE-2002-2290, change the default username and password for the admin account immediately after installation.
What software is affected by CVE-2002-2290?
CVE-2002-2290 specifically affects Mambo Site Server version 4.0.11.
Can CVE-2002-2290 be exploited remotely?
Yes, CVE-2002-2290 can be exploited remotely due to the presence of default admin credentials.
What are the potential risks associated with CVE-2002-2290?
The potential risks include unauthorized access and control over the Mambo Site Server, leading to data breaches or service disruptions.