CVE-2002-2247

Mambo Site Server 4.0.11 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-2247. PoCs published by euronymous.

AI-analyzed exploit summary The exploit describes an information disclosure vulnerability in Mambo Site Server due to the presence of a default phpinfo.php script in the administrator directory. This script can be accessed remotely to leak server configuration details.

Description

The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.

Exploits (1)

exploitdb WRITEUP VERIFIED
by euronymous · textwebappsphp
https://www.exploit-db.com/exploits/22086

The exploit describes an information disclosure vulnerability in Mambo Site Server due to the presence of a default phpinfo.php script in the administrator directory. This script can be accessed remotely to leak server configuration details.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Mambo Site Server (version not specified)
No auth needed
Prerequisites: Mambo Site Server installed with default configuration
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10853
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-12/0111.html
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6376

Scores

EPSS 0.0257
EPSS Percentile 83.1%

Details

CWE
CWE-16
Status published
Products (1)
mambo/mambo_site_server 4.0.11
Published Dec 31, 2002
Tracked Since Feb 18, 2026