OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Mambo 4.6.3 Path Disclosure, XSS , XSRF, DOS

jamboomlagmail.com
Date: Wed Feb 27 2008 - 06:04:18 CST


These vulnerabilities in the MOStlyCE editor were fixed and a new release made within 2 days of the Mambo Team being notified of the vulnerabilities.
http://forum.mambo-foundation.org/showthread.php?t=10158

Please Note: it is useful to notify Mambo whenever any risk is identified. Mambo is NOT at mamboserver.com. The project home is http://mambo-foundation.org.