Skip to main content

Vendor/product archive

mambo / mambo CVEs

Beta · best-effort

40 CVEs tagged to mambo / mambo0 Critical, 27 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2009-3333

Published Sep 23, 2009

PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-6814

Published May 28, 2009

Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5226

Published Nov 25, 2008

SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4777

Published Oct 29, 2008

SQL injection vulnerability in the Showroom Joomlearn LMS (com_lms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3712

Published Aug 19, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via t…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-2905

Published Jun 30, 2008

PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote att…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0795

Published Feb 15, 2008

SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6455

Published Dec 20, 2007

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Itemid parameter in a com…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5177

Published Oct 3, 2007

SQL injection vulnerability in index.php in the MambAds (com_mambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid pa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2