Skip to main content

Vendor/product archive

mambo-foundation / mambo CVEs

Beta · best-effort

21 CVEs tagged to mambo-foundation / mambo1 Critical, 10 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2011-2917

Published Dec 8, 2011

SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3754

Published Sep 23, 2011

Mambo 4.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4474

Published Dec 30, 2009

SQL injection vulnerability in the Mike de Boer zoom (com_zoom) component 2.0 for Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7215

Published Sep 11, 2009

The Image Manager in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to rename arbitrary files and cause a denial of service via modified file[New…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7214

Published Sep 11, 2009

Cross-site request forgery (CSRF) vulnerability in administrator/index2.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to hijack the authe…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7213

Published Sep 11, 2009

Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7212

Published Sep 11, 2009

MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/editors/mostlyce/jscripts/tiny_mce…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2497

Published May 28, 2008

CRLF injection vulnerability in Mambo before 4.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2498

Published May 28, 2008

Multiple SQL injection vulnerabilities in index.php in Mambo before 4.6.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1957

Published Apr 21, 2006

The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple reque…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1