Product: Mambo Open Source v4.5 Mambo Open Source v4.6 (CVS) Vendor: Miro International Pty Ltd. Author: FraMe ( frame at kernelpanik.org ) URL: http://www.kernelpanik.org CONTENTS 1. Overview 2. Description. 3. Details 4. Patches. 1. Overview. Mambo Open Source is an, open source, modular, web content management system (CMS), written in Php with a MySql database in backend. More info: http://www.mamboserver.com 2. Description. Mambo OS allow remote command execution in ./modules/mod_mainmenu.php Anybody can inject a url in $mosConfig_absolute_path and obtain command execution with web server privileges ( usually nobody ). 3. Details. Mambo OS v4.5 and v4.6 from ./modules/mod_mainmenu.php: ================================ 4. Patches a) Php globals off (Default in Php > 4.2) b) Unofficial patch for mod_mainmenu.php can be downloaded from: http://www.kernelpanik.org/code/kernelpanik/mambo.zip ============================== [ FraMe - frame at kernelpanik.org ] [ URL - http://frame.lifefromthenet.com ] [ Kernelpanik - http://www.kernelpanik.org ] [ PGP KeyID - 0xFA81AC9C ] ==============================