Mambo records
123 published records for vendor mambo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.8%
- Pre-auth RCE
- 96
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')50
- CWE-94 Improper Control of Generation of Code ('Code Injection')15
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-16 Configuration1
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
123 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2007-1699Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allojoomla · swmenu component | Critical10.0 | — | 10.6% | Mar 26, 2007 |
41Plan | CVE-2001-1011No exploit | index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID mambo · mambo site server | Critical10.0 | — | 4.4% | Jul 25, 2001 |
41Plan | CVE-2003-1245Proof of concept | index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash ofmambo · mambo site server | Critical10.0 | — | 4.1% | Dec 31, 2003 |
41Plan | CVE-2002-2290No exploit | Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.mambo · mambo site server · CWE-255 | Critical10.0 | — | 1.8% | Dec 31, 2002 |
40Plan | CVE-2006-4264No exploit | Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers tmambo · mtg myhomepage component | Critical9.8 | — | 1.8% | Aug 21, 2006 |
39Monitor | CVE-2007-1596Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow rjoomla · nfn address book | Critical9.3 | — | 7.8% | Mar 22, 2007 |
38Monitor | CVE-2007-5362Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Jmambo · mambo · CWE-94 | Medium6.8 | — | 36.5% | Oct 10, 2007 |
38Monitor | CVE-2007-4203No exploit | Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.mambo · mambo open source · CWE-287 | Critical9.3 | — | 1.9% | Aug 7, 2007 |
38Monitor | CVE-2005-4156No exploit | Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrarmambo · mambo open source 4.5 | Critical9.4 | — | 1.8% | Dec 10, 2005 |
33Monitor | CVE-2008-2905Weaponized | PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when registemambo · mambo · CWE-94 | Medium6.8 | — | 18.4% | Jun 30, 2008 |
32Monitor | CVE-2006-1794Proof of concept | SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands mambo · mambo | High7.6 | — | 5.5% | Apr 17, 2006 |
31Monitor | CVE-2006-4296Proof of concept | PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers tmambo · bigape-backup component | High7.5 | — | 3.5% | Aug 22, 2006 |
31Monitor | CVE-2006-3736Proof of concept | PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attacmambo · videodb | High7.5 | — | 3.3% | Jul 21, 2006 |
31Monitor | CVE-2004-1693Proof of concept | PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifymambo · mambo | High7.5 | — | 3.0% | Sep 18, 2004 |
31Monitor | CVE-2006-4269No exploit | PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allowjoomla · x-shop component | High7.5 | — | 2.8% | Aug 21, 2006 |
31Monitor | CVE-2006-6634Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote atmambo · extcalthai module | High7.5 | — | 2.7% | Dec 18, 2006 |
31Monitor | CVE-2006-3843Proof of concept | PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute armambo · mambo calendar | High7.5 | — | 2.6% | Jul 25, 2006 |
31Monitor | CVE-2006-3262Proof of concept | SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary Smambo · mambo | High7.5 | — | 2.5% | Jun 27, 2006 |
31Monitor | CVE-2007-4456Proof of concept | SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrmambo · mambo · CWE-89 | High7.5 | — | 2.4% | Aug 21, 2007 |
31Monitor | CVE-2006-7104Proof of concept | PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a compomambo · mostlyce · CWE-94 | High7.5 | — | 2.3% | Mar 3, 2007 |
31Monitor | CVE-2008-2990Proof of concept | PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! joomla · com facileforms · CWE-94 | High7.5 | — | 2.3% | Jul 2, 2008 |
31Monitor | CVE-2006-3962Proof of concept | PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (cmambo · bayesiannaivefilter | High7.5 | — | 2.2% | Aug 1, 2006 |
31Monitor | CVE-2009-0726Proof of concept | SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrarygigcalendar · com gigcalendar · CWE-89 | High7.5 | — | 2.0% | Feb 24, 2009 |
31Monitor | CVE-2008-6653Proof of concept | SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allowjoomla · joomla · CWE-89 | High7.5 | — | 2.0% | Apr 7, 2009 |
31Monitor | CVE-2008-5208Proof of concept | SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execjoomla · com datsogallery · CWE-89 | High7.5 | — | 2.0% | Nov 24, 2008 |
- CVE-2007-169943Plan
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allo
CriticalCVSS 10.0Proof of conceptEPSS 11%joomla · swmenu componentMar 26, 2007
- CVE-2001-101141Plan
index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID
CriticalCVSS 10.0No exploitEPSS 4%mambo · mambo site serverJul 25, 2001
- CVE-2003-124541Plan
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of
CriticalCVSS 10.0Proof of conceptEPSS 4%mambo · mambo site serverDec 31, 2003
- CVE-2002-229041Plan
Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.
CriticalCVSS 10.0No exploitEPSS 2%mambo · mambo site serverDec 31, 2002
- CVE-2006-426440Plan
Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers t
CriticalCVSS 9.8No exploitEPSS 2%mambo · mtg myhomepage componentAug 21, 2006
- CVE-2007-159639Monitor
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow r
CriticalCVSS 9.3Proof of conceptEPSS 8%joomla · nfn address bookMar 22, 2007
- CVE-2007-536238Monitor
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and J
MediumCVSS 6.8Proof of conceptEPSS 37%mambo · mamboOct 10, 2007
- CVE-2007-420338Monitor
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
CriticalCVSS 9.3No exploitEPSS 2%mambo · mambo open sourceAug 7, 2007
- CVE-2005-415638Monitor
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrar
CriticalCVSS 9.4No exploitEPSS 2%mambo · mambo open source 4.5Dec 10, 2005
- CVE-2008-290533Monitor
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when registe
MediumCVSS 6.8WeaponizedEPSS 18%mambo · mamboJun 30, 2008
- CVE-2006-179432Monitor
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.6Proof of conceptEPSS 6%mambo · mamboApr 17, 2006
- CVE-2006-429631Monitor
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers t
HighCVSS 7.5Proof of conceptEPSS 3%mambo · bigape-backup componentAug 22, 2006
- CVE-2006-373631Monitor
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attac
HighCVSS 7.5Proof of conceptEPSS 3%mambo · videodbJul 21, 2006
- CVE-2004-169331Monitor
PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modify
HighCVSS 7.5Proof of conceptEPSS 3%mambo · mamboSep 18, 2004
- CVE-2006-426931Monitor
PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allow
HighCVSS 7.5No exploitEPSS 3%joomla · x-shop componentAug 21, 2006
- CVE-2006-663431Monitor
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote at
HighCVSS 7.5Proof of conceptEPSS 3%mambo · extcalthai moduleDec 18, 2006
- CVE-2006-384331Monitor
PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute ar
HighCVSS 7.5Proof of conceptEPSS 3%mambo · mambo calendarJul 25, 2006
- CVE-2006-326231Monitor
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary S
HighCVSS 7.5Proof of conceptEPSS 2%mambo · mamboJun 27, 2006
- CVE-2007-445631Monitor
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitr
HighCVSS 7.5Proof of conceptEPSS 2%mambo · mamboAug 21, 2007
- CVE-2006-710431Monitor
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a compo
HighCVSS 7.5Proof of conceptEPSS 2%mambo · mostlyceMar 3, 2007
- CVE-2008-299031Monitor
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla!
HighCVSS 7.5Proof of conceptEPSS 2%joomla · com facileformsJul 2, 2008
- CVE-2006-396231Monitor
PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (c
HighCVSS 7.5Proof of conceptEPSS 2%mambo · bayesiannaivefilterAug 1, 2006
- CVE-2009-072631Monitor
SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary
HighCVSS 7.5Proof of conceptEPSS 2%gigcalendar · com gigcalendarFeb 24, 2009
- CVE-2008-665331Monitor
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allow
HighCVSS 7.5Proof of conceptEPSS 2%joomla · joomlaApr 7, 2009
- CVE-2008-520831Monitor
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to exec
HighCVSS 7.5Proof of conceptEPSS 2%joomla · com datsogalleryNov 24, 2008