CVE-2008-2905

Mambo - Code Injection

Title source: rule

Description

PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16912
exploitdb WORKING POC VERIFIED
by MC · rubywebappsphp
https://www.exploit-db.com/exploits/9906
exploitdb WORKING POC VERIFIED
by irk4z · textwebappsphp
https://www.exploit-db.com/exploits/5808
metasploit WORKING POC EXCELLENT
by MC · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/mambo_cache_lite.rb

Scores

EPSS 0.7217
EPSS Percentile 98.8%

Details

CWE
CWE-94
Status published
Products (23)
mambo/mambo 4.0.14
mambo/mambo 4.5
mambo/mambo 4.5.0.2
mambo/mambo 4.5.1.3
mambo/mambo 4.5.1_1.0.9
mambo/mambo 4.5.1_beta
mambo/mambo 4.5.1_beta2
mambo/mambo 4.5.1a
mambo/mambo 4.5.2
mambo/mambo 4.5.2.1
... and 13 more
Published Jun 30, 2008
Tracked Since Feb 18, 2026