globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content.html.php for remote PHP file inclusion.
| Software | From | Fixed in |
|---|---|---|
| mambo / mambo_site_server | 4.0.12 | 4.0.12.x |
| mambo / mambo_site_server | 4.0.14 | 4.0.14.x |
| mambo / mambo_site_server | 4.0.12_rc1 | 4.0.12_rc1.x |
| mambo / mambo_site_server | 4.0.12_beta | 4.0.12_beta.x |
| mambo / mambo_site_server | 4.0.12_beta_2 | 4.0.12_beta_2.x |
| mambo / mambo_site_server | 4.0.11 | 4.0.11.x |
| mambo / mambo_site_server | 4.0.12_rc2 | 4.0.12_rc2.x |
| mambo / mambo_site_server | 4.0 | 4.0.x |
| mambo / mambo_site_server | 4.0.12_rc3 | 4.0.12_rc3.x |
| mambo / mambo_site_server | 4.0.10 | 4.0.10.x |