index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where sessionid is set to the MD5 hash of a session cookie.
globals.php in Mambo Site Server 4.0.14 and earlier, when registerglobals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfigabsolutepath parameter to content.html.php for remote PHP file inclusion.