CVE-2002-2288
Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that does not exist, which causes the path to be leaked in an error message.
Scoring
- CVSS base score
- 0.26
- EPSS probability
- 5.27%
- Published
- 2007-10-18
- Last modified
- 2026-03-16
Affected products
- n/a n/a