First published: Fri Feb 15 2019(Updated: )
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
Credit: larry0@me.com
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pnphpbb | =4.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-2565 is considered medium due to its potential exposure of sensitive server path information.
To fix CVE-2013-2565, upgrade Mambo CMS to a version that does not include this vulnerability.
CVE-2013-2565 can potentially provide attackers with the root path of the web server, which may facilitate further exploitation.
Yes, CVE-2013-2565 can be exploited remotely if the vulnerable scripts are accessible over the internet.
CVE-2013-2565 specifically affects Mambo CMS version 4.6.5.