CVE-2003-1245: Critical severity mambo mambo site server vulnerability
Published Dec 31, 2003
·Updated
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where sessionid is set to the MD5 hash of a session cookie.
Affected Software
2 affected components
Mambo Mambo Site Server=4.0.12_rc2
Mambo Mambo Site Server=4.0.12_rc2
Remediation
Patch Available
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Nov 16, 2005
CVE Published
via MITRE·12:37 PM
Data Sourced
via MITRE·12:37 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1245?
CVE-2003-1245 is considered a high severity vulnerability due to the potential for unauthorized administrative access.
2
How do I fix CVE-2003-1245?
To fix CVE-2003-1245, upgrade to a patched version of Mambo beyond 4.0.12, which addresses this vulnerability.
3
What type of attacks can be performed due to CVE-2003-1245?
Exploitation of CVE-2003-1245 allows attackers to gain unauthorized administrator access to the Mambo site.
4
What software versions are affected by CVE-2003-1245?
CVE-2003-1245 specifically affects Mambo 4.0.12 and its RC2 version.
5
Is there a known exploit for CVE-2003-1245?
Yes, there are publicly known exploits that leverage CVE-2003-1245 to compromise the Mambo application.