Skip to main content

Vendor archive

mambo CVEs

Beta · best-effort

123 CVEs tagged to vendor mambo8 Critical, 77 High, 36 Medium, 2 Low, 0 Unrated.

CVE-2009-3333

Published Sep 23, 2009

PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6814

Published May 28, 2009

Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5226

Published Nov 25, 2008

SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4777

Published Oct 29, 2008

SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3712

Published Aug 19, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via t…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-2905

Published Jun 30, 2008

PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote att…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2500

Published May 29, 2008

Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor (MOStlyCE) component before 3.0 for Mambo allows remote attackers to inject arbitrary web script or HTML via u…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1540

Published Mar 28, 2008

SQL injection vulnerability in the Datsogallery (com_datsogallery) 1.3.1 module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id paramete…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0849

Published Feb 21, 2008

SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 123 CVEsPage 1 of 5