First published: Mon Jun 09 2014(Updated: )
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo CMS | =4.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2562 is considered a high severity vulnerability due to the risk of exposing sensitive database credentials.
To fix CVE-2013-2562, you should relocate the configuration file that contains the MySQL database password to a non-accessible directory from the web root.
CVE-2013-2562 affects users of Mambo CMS version 4.6.5.
CVE-2013-2562 exposes the MySQL database password in cleartext, which can lead to unauthorized access to the database.
Yes, CVE-2013-2562 can be exploited by local users who have access to the document root of the Mambo CMS installation.