Mambo

Mambo

26 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.08%
  • Published 17.04.2006 10:02:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck fun...

  • EPSS 1.15%
  • Published 24.02.2006 11:02:00
  • Last modified 03.04.2025 01:03:51

Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assi...

Exploit
  • EPSS 0.41%
  • Published 16.11.2005 07:42:00
  • Last modified 03.04.2025 01:03:51

content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the application to return an error.

  • EPSS 1.34%
  • Published 15.06.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.

  • EPSS 0.75%
  • Published 21.02.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different v...

Exploit
  • EPSS 9.52%
  • Published 18.09.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code.