Forum Moderators: phranque

Message Too Old, No Replies

Major security hole in Mambo CMS detected!

Fixes available!

         

pmkpmk

1:24 pm on Feb 4, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Yesterday evening a large security hole was discovered in Mambo. Abusing global variables a possible attacker can get admin access to your website and to your database. The hole is present in all versions of Mambo, the old 4.5 version and the actual version 4.5.1.

More background information at [mamboportal.com...]

trillianjedi

1:53 pm on Feb 4, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Ouch.

Thanks for the heads up pmk.