First published: Mon Feb 21 2005(Updated: )
PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2004-1693.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo (MamboCMS) | <=4.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0512 is considered a critical vulnerability due to its ability to allow remote code execution.
To fix CVE-2005-0512, upgrade Mambo to a version later than 4.5.2.1.
CVE-2005-0512 affects Mambo versions up to and including 4.5.2.
CVE-2005-0512 is a remote file inclusion vulnerability.
Yes, exploitation of CVE-2005-0512 can potentially lead to full system compromise.