CVE-2005-3738

EXPLOITED

Mambo Site Server <4.0.14 - RCE

Title source: llm

Description

globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1337

Scores

EPSS 0.0549
EPSS Percentile 90.2%

Details

VulnCheck KEV 2005-11-22
Status published
Products (10)
mambo/mambo_site_server 4.0
mambo/mambo_site_server 4.0.10
mambo/mambo_site_server 4.0.11
mambo/mambo_site_server 4.0.12
mambo/mambo_site_server 4.0.12_beta
mambo/mambo_site_server 4.0.12_beta_2
mambo/mambo_site_server 4.0.12_rc1
mambo/mambo_site_server 4.0.12_rc2
mambo/mambo_site_server 4.0.12_rc3
mambo/mambo_site_server 4.0.14
Published Nov 22, 2005
Tracked Since Feb 18, 2026