Vulnerability Description
The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers to read certain content via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mambo | Mambo Open Source | 4.6.1 |
References
- http://secunia.com/advisories/25039PatchVendor Advisory
- http://www.securityfocus.com/bid/23787
- http://www.tracker.mambo-foundation.org/?do=details&task_id=170
- http://secunia.com/advisories/25039PatchVendor Advisory
- http://www.securityfocus.com/bid/23787
- http://www.tracker.mambo-foundation.org/?do=details&task_id=170
FAQ
What is CVE-2006-7202?
CVE-2006-7202 is a vulnerability with a CVSS score of 7.8 (HIGH). The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers to read certain content via unspecified vectors.
How severe is CVE-2006-7202?
CVE-2006-7202 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-7202?
Check the references section above for vendor advisories and patch information. Affected products include: Mambo Mambo Open Source.