CVE-2013-2563: Low severity Mambo-foundation Mambo Cms vulnerability
Published Jun 9, 2014
·Updated
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.
Affected Software
1 affected component
Mambo-foundation Mambo Cms=4.6.5
Event History
Jun 9, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-2563?
CVE-2013-2563 is considered a medium severity vulnerability due to the exposure of sensitive information.
2
How does CVE-2013-2563 affect Mambo CMS?
CVE-2013-2563 allows local users to read the configuration.php file, potentially exposing the admin password hash.
3
Who is affected by CVE-2013-2563?
Users running Mambo CMS version 4.6.5 are affected by CVE-2013-2563.
4
How do I fix CVE-2013-2563?
To fix CVE-2013-2563, ensure that the permissions on configuration.php are restricted and not world-readable.
5
What are the potential risks of CVE-2013-2563?
The risks include unauthorized access to admin credentials and further exploitation of the Mambo CMS installation.