Hole in Galleria module for Mambo CMS
Users of the Mambo content management system may have to check the configuration of their server to ensure security - at least if they are using the Galleria module. A flaw in version 1.0 of the module can be exploited to compromise the server. The problem is caused by a lack of a filter for the parameter mosConfig_absolute_path in galleria.html.php, which attackers can use to inject and execute their own PHP scripts. However, the option register_globals must be activated for an attack to succeed. Recently, a very similar hole was also found in the CBSMS module, which sends text messages (SMS).
If you are checking your system anyway, you can also think about switching to Mambo 4.6 RC2, which closed the SQL injection hole made public last week. A patch for 4.6 RC1 and 4.5.x also remedies the problem.
- Mambo Galleria Module "mosConfig_absolute_path" File Inclusion, Secunia's security advisory