The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root path via phpinfo.php, which calls the phpinfo function.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/10853 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2002-12/0111.html | mailing list |
http://www.securityfocus.com/bid/6376 | patch vdb entry exploit |