The latest Mambo is very good at reminding people to remove your installation directory after install is complete. Earlier versions do not have that reminder. If you do not remove your installation directory your site will be vulnerable.
If you are using a version of Mambo that does not block you from accessing your site until you have removed the installation directory it is strongly advised that you upgrade. You should always be using the latest releases as these are the most secure.
Note: Do not be tempted to just rename the directory. Although renaming will trick Mambo into thinking the install files have been removed from your site, leaving the directory there does create a security risk. Remove completely. If you ever need the files again you can always download them from the Mambo forge.







