Skip to content
Noroxi

Mambo records

123 published records for vendor mambo.

All records

123 records
  • Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allo

    CriticalCVSS 10.0Proof of conceptEPSS 11%

    joomla · swmenu componentMar 26, 2007

  • index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID

    CriticalCVSS 10.0No exploitEPSS 4%

    mambo · mambo site serverJul 25, 2001

  • index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of

    CriticalCVSS 10.0Proof of conceptEPSS 4%

    mambo · mambo site serverDec 31, 2003

  • Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.

    CriticalCVSS 10.0No exploitEPSS 2%

    mambo · mambo site serverDec 31, 2002

  • Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers t

    CriticalCVSS 9.8No exploitEPSS 2%

    mambo · mtg myhomepage componentAug 21, 2006

  • CVE-2007-1596
    39Monitor

    Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow r

    CriticalCVSS 9.3Proof of conceptEPSS 8%

    joomla · nfn address bookMar 22, 2007

  • CVE-2007-5362
    38Monitor

    Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and J

    MediumCVSS 6.8Proof of conceptEPSS 37%

    mambo · mamboOct 10, 2007

  • CVE-2007-4203
    38Monitor

    Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.

    CriticalCVSS 9.3No exploitEPSS 2%

    mambo · mambo open sourceAug 7, 2007

  • CVE-2005-4156
    38Monitor

    Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrar

    CriticalCVSS 9.4No exploitEPSS 2%

    mambo · mambo open source 4.5Dec 10, 2005

  • CVE-2008-2905
    33Monitor

    PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when registe

    MediumCVSS 6.8WeaponizedEPSS 18%

    mambo · mamboJun 30, 2008

  • CVE-2006-1794
    32Monitor

    SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands

    HighCVSS 7.6Proof of conceptEPSS 6%

    mambo · mamboApr 17, 2006

  • CVE-2006-4296
    31Monitor

    PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers t

    HighCVSS 7.5Proof of conceptEPSS 3%

    mambo · bigape-backup componentAug 22, 2006

  • CVE-2006-3736
    31Monitor

    PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attac

    HighCVSS 7.5Proof of conceptEPSS 3%

    mambo · videodbJul 21, 2006

  • CVE-2004-1693
    31Monitor

    PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modify

    HighCVSS 7.5Proof of conceptEPSS 3%

    mambo · mamboSep 18, 2004

  • CVE-2006-4269
    31Monitor

    PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allow

    HighCVSS 7.5No exploitEPSS 3%

    joomla · x-shop componentAug 21, 2006

  • CVE-2006-6634
    31Monitor

    Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote at

    HighCVSS 7.5Proof of conceptEPSS 3%

    mambo · extcalthai moduleDec 18, 2006

  • CVE-2006-3843
    31Monitor

    PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute ar

    HighCVSS 7.5Proof of conceptEPSS 3%

    mambo · mambo calendarJul 25, 2006

  • CVE-2006-3262
    31Monitor

    SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary S

    HighCVSS 7.5Proof of conceptEPSS 2%

    mambo · mamboJun 27, 2006

  • CVE-2007-4456
    31Monitor

    SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitr

    HighCVSS 7.5Proof of conceptEPSS 2%

    mambo · mamboAug 21, 2007

  • CVE-2006-7104
    31Monitor

    PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a compo

    HighCVSS 7.5Proof of conceptEPSS 2%

    mambo · mostlyceMar 3, 2007

  • CVE-2008-2990
    31Monitor

    PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla!

    HighCVSS 7.5Proof of conceptEPSS 2%

    joomla · com facileformsJul 2, 2008

  • CVE-2006-3962
    31Monitor

    PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (c

    HighCVSS 7.5Proof of conceptEPSS 2%

    mambo · bayesiannaivefilterAug 1, 2006

  • CVE-2009-0726
    31Monitor

    SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary

    HighCVSS 7.5Proof of conceptEPSS 2%

    gigcalendar · com gigcalendarFeb 24, 2009

  • CVE-2008-6653
    31Monitor

    SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allow

    HighCVSS 7.5Proof of conceptEPSS 2%

    joomla · joomlaApr 7, 2009

  • CVE-2008-5208
    31Monitor

    SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to exec

    HighCVSS 7.5Proof of conceptEPSS 2%

    joomla · com datsogalleryNov 24, 2008