Mambo Undisclosed Authentication Bypass

high Nessus Network Monitor Plugin ID 3444

Synopsis

The remote host is vulnerable to a flaw that allows for the bypassing of authentication.

Description

The remote host is running the Mambo Content Server, an application for generating dynamic content for web servers. The remote application is vulnerable to a flaw where remote attackers can bypass authentication and access confidential data. The exact details of the flaw are unknown; however, it is believed that an attacker exploiting this flaw would be able to access confidential data that was readable by the web server process.

Solution

Upgrade or patch according to vendor recommendations.

See Also

http://www.mamboserver.com

Plugin Details

Severity: High

ID: 3444

Family: Web Servers

Published: 2/22/2006

Updated: 3/6/2019

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:mambo:mambo

Reference Information

CVE: CVE-2006-1794, CVE-2006-3263

BID: 16775