First published: Wed May 09 2007(Updated: )
The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers to read certain content via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo Open Source | =4.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-7202 has a high severity rating due to unauthorized access to sensitive content.
To fix CVE-2006-7202, you should update Mambo to a version where this vulnerability is patched.
CVE-2006-7202 specifically affects Mambo version 4.6.1.
CVE-2006-7202 is an access control vulnerability that allows remote attackers to read database content.
Yes, CVE-2006-7202 can be exploited remotely by attackers to gain unauthorized access to data.