Записи Mambo
123 опубликованных записей вендора mambo.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,8 %
- Pre-auth RCE
- 96
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')50
- CWE-94 Improper Control of Generation of Code ('Code Injection')15
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-16 Configuration1
- CWE-399 Resource Management Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
123 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2007-1699Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allojoomla · swmenu component | Критическая10,0 | — | 10,6 % | 26 мар. 2007 г. |
41В плане | CVE-2001-1011Эксплойта нет | index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID mambo · mambo site server | Критическая10,0 | — | 4,4 % | 25 июл. 2001 г. |
41В плане | CVE-2003-1245Proof of concept | index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash ofmambo · mambo site server | Критическая10,0 | — | 4,1 % | 31 дек. 2003 г. |
41В плане | CVE-2002-2290Эксплойта нет | Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.mambo · mambo site server · CWE-255 | Критическая10,0 | — | 1,8 % | 31 дек. 2002 г. |
40В плане | CVE-2006-4264Эксплойта нет | Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers tmambo · mtg myhomepage component | Критическая9,8 | — | 1,8 % | 21 авг. 2006 г. |
39Наблюдать | CVE-2007-1596Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow rjoomla · nfn address book | Критическая9,3 | — | 7,8 % | 22 мар. 2007 г. |
38Наблюдать | CVE-2007-5362Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Jmambo · mambo · CWE-94 | Средняя6,8 | — | 36,5 % | 10 окт. 2007 г. |
38Наблюдать | CVE-2007-4203Эксплойта нет | Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.mambo · mambo open source · CWE-287 | Критическая9,3 | — | 1,9 % | 7 авг. 2007 г. |
38Наблюдать | CVE-2005-4156Эксплойта нет | Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrarmambo · mambo open source 4.5 | Критическая9,4 | — | 1,8 % | 10 дек. 2005 г. |
33Наблюдать | CVE-2008-2905Готовый эксплойт | PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when registemambo · mambo · CWE-94 | Средняя6,8 | — | 18,4 % | 30 июн. 2008 г. |
32Наблюдать | CVE-2006-1794Proof of concept | SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands mambo · mambo | Высокая7,6 | — | 5,5 % | 17 апр. 2006 г. |
31Наблюдать | CVE-2006-4296Proof of concept | PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers tmambo · bigape-backup component | Высокая7,5 | — | 3,5 % | 22 авг. 2006 г. |
31Наблюдать | CVE-2006-3736Proof of concept | PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attacmambo · videodb | Высокая7,5 | — | 3,3 % | 21 июл. 2006 г. |
31Наблюдать | CVE-2004-1693Proof of concept | PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifymambo · mambo | Высокая7,5 | — | 3,0 % | 18 сент. 2004 г. |
31Наблюдать | CVE-2006-4269Эксплойта нет | PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allowjoomla · x-shop component | Высокая7,5 | — | 2,8 % | 21 авг. 2006 г. |
31Наблюдать | CVE-2006-6634Proof of concept | Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote atmambo · extcalthai module | Высокая7,5 | — | 2,7 % | 18 дек. 2006 г. |
31Наблюдать | CVE-2006-3843Proof of concept | PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute armambo · mambo calendar | Высокая7,5 | — | 2,6 % | 25 июл. 2006 г. |
31Наблюдать | CVE-2006-3262Proof of concept | SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary Smambo · mambo | Высокая7,5 | — | 2,5 % | 27 июн. 2006 г. |
31Наблюдать | CVE-2007-4456Proof of concept | SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrmambo · mambo · CWE-89 | Высокая7,5 | — | 2,4 % | 21 авг. 2007 г. |
31Наблюдать | CVE-2006-7104Proof of concept | PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a compomambo · mostlyce · CWE-94 | Высокая7,5 | — | 2,3 % | 3 мар. 2007 г. |
31Наблюдать | CVE-2008-2990Proof of concept | PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! joomla · com facileforms · CWE-94 | Высокая7,5 | — | 2,3 % | 2 июл. 2008 г. |
31Наблюдать | CVE-2006-3962Proof of concept | PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (cmambo · bayesiannaivefilter | Высокая7,5 | — | 2,2 % | 1 авг. 2006 г. |
31Наблюдать | CVE-2009-0726Proof of concept | SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrarygigcalendar · com gigcalendar · CWE-89 | Высокая7,5 | — | 2,0 % | 24 февр. 2009 г. |
31Наблюдать | CVE-2008-6653Proof of concept | SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allowjoomla · joomla · CWE-89 | Высокая7,5 | — | 2,0 % | 7 апр. 2009 г. |
31Наблюдать | CVE-2008-5208Proof of concept | SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execjoomla · com datsogallery · CWE-89 | Высокая7,5 | — | 2,0 % | 24 нояб. 2008 г. |
- CVE-2007-169943В плане
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allo
КритическаяCVSS 10,0Proof of conceptEPSS 11 %joomla · swmenu component26 мар. 2007 г.
- CVE-2001-101141В плане
index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %mambo · mambo site server25 июл. 2001 г.
- CVE-2003-124541В плане
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of
КритическаяCVSS 10,0Proof of conceptEPSS 4 %mambo · mambo site server31 дек. 2003 г.
- CVE-2002-229041В плане
Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %mambo · mambo site server31 дек. 2002 г.
- CVE-2006-426440В плане
Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers t
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mambo · mtg myhomepage component21 авг. 2006 г.
- CVE-2007-159639Наблюдать
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow r
КритическаяCVSS 9,3Proof of conceptEPSS 8 %joomla · nfn address book22 мар. 2007 г.
- CVE-2007-536238Наблюдать
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and J
СредняяCVSS 6,8Proof of conceptEPSS 37 %mambo · mambo10 окт. 2007 г.
- CVE-2007-420338Наблюдать
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %mambo · mambo open source7 авг. 2007 г.
- CVE-2005-415638Наблюдать
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrar
КритическаяCVSS 9,4Эксплойта нетEPSS 2 %mambo · mambo open source 4.510 дек. 2005 г.
- CVE-2008-290533Наблюдать
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when registe
СредняяCVSS 6,8Готовый эксплойтEPSS 18 %mambo · mambo30 июн. 2008 г.
- CVE-2006-179432Наблюдать
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,6Proof of conceptEPSS 6 %mambo · mambo17 апр. 2006 г.
- CVE-2006-429631Наблюдать
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers t
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %mambo · bigape-backup component22 авг. 2006 г.
- CVE-2006-373631Наблюдать
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attac
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %mambo · videodb21 июл. 2006 г.
- CVE-2004-169331Наблюдать
PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modify
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %mambo · mambo18 сент. 2004 г.
- CVE-2006-426931Наблюдать
PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allow
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %joomla · x-shop component21 авг. 2006 г.
- CVE-2006-663431Наблюдать
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote at
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %mambo · extcalthai module18 дек. 2006 г.
- CVE-2006-384331Наблюдать
PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute ar
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %mambo · mambo calendar25 июл. 2006 г.
- CVE-2006-326231Наблюдать
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary S
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %mambo · mambo27 июн. 2006 г.
- CVE-2007-445631Наблюдать
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitr
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %mambo · mambo21 авг. 2007 г.
- CVE-2006-710431Наблюдать
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a compo
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %mambo · mostlyce3 мар. 2007 г.
- CVE-2008-299031Наблюдать
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla!
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %joomla · com facileforms2 июл. 2008 г.
- CVE-2006-396231Наблюдать
PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (c
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %mambo · bayesiannaivefilter1 авг. 2006 г.
- CVE-2009-072631Наблюдать
SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %gigcalendar · com gigcalendar24 февр. 2009 г.
- CVE-2008-665331Наблюдать
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allow
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %joomla · joomla7 апр. 2009 г.
- CVE-2008-520831Наблюдать
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to exec
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %joomla · com datsogallery24 нояб. 2008 г.