« Volver al listado

CVE-2005-3738

Estado: ModificadaBaja (2.6)—

globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2005-3738",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2005-11-22T11:03:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0520.html",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://forum.mamboserver.com/showthread.php?t=66154",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/17622",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1015258",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/417215",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/426942/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/427196/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/15461",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2005/2473",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0520.html",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://forum.mamboserver.com/showthread.php?t=66154",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/17622",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1015258",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/417215",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/426942/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/427196/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/15461",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2005/2473",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion."
    },
    {
      "lang": "es",
      "value": "globals.php en Mambo Site Server 4.0.14 y anteriores, cuando \"register_globals\" está desactivado, permite a atacantes remotos sobreescribir variables mediante el 'array' \"GLOBALS\" y llevar a cabo varios ataques, como se ha demostrado usando el parámetro \"mosConfig_absolute_path\" de content.html.php para inclusión remota de PHP."
    }
  ],
  "lastModified": "2026-06-16T22:17:31.857",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE4760B9-54F5-493C-A11E-B77DA6EC6C97"
            },
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DD99A44A-B0C5-4C4F-A2C5-E887A50D524A"
            },
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CCB5F323-A895-4392-8801-17A91A3DF23A"
            },
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0ED5902-9239-426B-BAE1-43B0B81D3698"
            },
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0.12_beta:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D336F35-29A5-4937-AFD9-A270FBBCAF41"
            },
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0.12_beta_2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99ECD749-5ACB-4322-9176-E2818A375507"
            },
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0.12_rc1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93111FE2-AB73-41D4-96B8-6C6FD1C36708"
            },
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0.12_rc2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6FA85FE-1057-4BA8-B706-7590290E7BA5"
            },
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0.12_rc3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C4800B71-007D-41C8-8450-EF06D7920E50"
            },
            {
              "criteria": "cpe:2.3:a:mambo:mambo_site_server:4.0.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE093E4B-37EB-4DB9-A6BD-5C22251E6F88"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}