CVE-2013-2565: Path Traversal
Published Feb 15, 2019
·Updated
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
Affected Software
1 affected component
Mambo-foundation Mambo Cms=4.6.5
Event History
Feb 15, 2019
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2013-2565?
The severity of CVE-2013-2565 is considered medium due to its potential exposure of sensitive server path information.
2
How do I fix CVE-2013-2565?
To fix CVE-2013-2565, upgrade Mambo CMS to a version that does not include this vulnerability.
3
What impact does CVE-2013-2565 have on my system?
CVE-2013-2565 can potentially provide attackers with the root path of the web server, which may facilitate further exploitation.
4
Is CVE-2013-2565 exploitable remotely?
Yes, CVE-2013-2565 can be exploited remotely if the vulnerable scripts are accessible over the internet.
5
Which versions of Mambo CMS are affected by CVE-2013-2565?
CVE-2013-2565 specifically affects Mambo CMS version 4.6.5.