index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mambo_site_server | Mambo | 3.0 (including) | 3.0 (including) |
| Mambo_site_server | Mambo | 3.0.1 (including) | 3.0.1 (including) |
| Mambo_site_server | Mambo | 3.0.2 (including) | 3.0.2 (including) |
| Mambo_site_server | Mambo | 3.0.3 (including) | 3.0.3 (including) |
| Mambo_site_server | Mambo | 3.0.4 (including) | 3.0.4 (including) |
| Mambo_site_server | Mambo | 3.0.5 (including) | 3.0.5 (including) |