CVE
- Id
- 14942
- CVE No.
- CVE-2005-3738
- Status
- Candidate
- Description
- globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.
- Phase
- Assigned (20051122)
- Votes
- None (candidate not yet proposed)
- Comments