Mambo kayıtları
mambo üreticisine ait 123 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,8
- Pre-auth RCE
- 96
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')50
- CWE-94 Improper Control of Generation of Code ('Code Injection')15
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-16 Configuration1
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
123 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2007-1699Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allojoomla · swmenu component | Kritik10,0 | — | %10,6 | 26 Mar 2007 |
41Planlayın | CVE-2001-1011İstismar yok | index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID mambo · mambo site server | Kritik10,0 | — | %4,4 | 25 Tem 2001 |
41Planlayın | CVE-2003-1245Kavram kanıtı | index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash ofmambo · mambo site server | Kritik10,0 | — | %4,1 | 31 Ara 2003 |
41Planlayın | CVE-2002-2290İstismar yok | Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.mambo · mambo site server · CWE-255 | Kritik10,0 | — | %1,8 | 31 Ara 2002 |
40Planlayın | CVE-2006-4264İstismar yok | Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers tmambo · mtg myhomepage component | Kritik9,8 | — | %1,8 | 21 Ağu 2006 |
39İzleyin | CVE-2007-1596Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow rjoomla · nfn address book | Kritik9,3 | — | %7,8 | 22 Mar 2007 |
38İzleyin | CVE-2007-5362Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Jmambo · mambo · CWE-94 | Orta6,8 | — | %36,5 | 10 Eki 2007 |
38İzleyin | CVE-2007-4203İstismar yok | Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.mambo · mambo open source · CWE-287 | Kritik9,3 | — | %1,9 | 7 Ağu 2007 |
38İzleyin | CVE-2005-4156İstismar yok | Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrarmambo · mambo open source 4.5 | Kritik9,4 | — | %1,8 | 10 Ara 2005 |
33İzleyin | CVE-2008-2905Silahlaştırılmış | PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when registemambo · mambo · CWE-94 | Orta6,8 | — | %18,4 | 30 Haz 2008 |
32İzleyin | CVE-2006-1794Kavram kanıtı | SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands mambo · mambo | Yüksek7,6 | — | %5,5 | 17 Nis 2006 |
31İzleyin | CVE-2006-4296Kavram kanıtı | PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers tmambo · bigape-backup component | Yüksek7,5 | — | %3,5 | 22 Ağu 2006 |
31İzleyin | CVE-2006-3736Kavram kanıtı | PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attacmambo · videodb | Yüksek7,5 | — | %3,3 | 21 Tem 2006 |
31İzleyin | CVE-2004-1693Kavram kanıtı | PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifymambo · mambo | Yüksek7,5 | — | %3,0 | 18 Eyl 2004 |
31İzleyin | CVE-2006-4269İstismar yok | PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allowjoomla · x-shop component | Yüksek7,5 | — | %2,8 | 21 Ağu 2006 |
31İzleyin | CVE-2006-6634Kavram kanıtı | Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote atmambo · extcalthai module | Yüksek7,5 | — | %2,7 | 18 Ara 2006 |
31İzleyin | CVE-2006-3843Kavram kanıtı | PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute armambo · mambo calendar | Yüksek7,5 | — | %2,6 | 25 Tem 2006 |
31İzleyin | CVE-2006-3262Kavram kanıtı | SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary Smambo · mambo | Yüksek7,5 | — | %2,5 | 27 Haz 2006 |
31İzleyin | CVE-2007-4456Kavram kanıtı | SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrmambo · mambo · CWE-89 | Yüksek7,5 | — | %2,4 | 21 Ağu 2007 |
31İzleyin | CVE-2006-7104Kavram kanıtı | PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a compomambo · mostlyce · CWE-94 | Yüksek7,5 | — | %2,3 | 3 Mar 2007 |
31İzleyin | CVE-2008-2990Kavram kanıtı | PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! joomla · com facileforms · CWE-94 | Yüksek7,5 | — | %2,3 | 2 Tem 2008 |
31İzleyin | CVE-2006-3962Kavram kanıtı | PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (cmambo · bayesiannaivefilter | Yüksek7,5 | — | %2,2 | 1 Ağu 2006 |
31İzleyin | CVE-2009-0726Kavram kanıtı | SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrarygigcalendar · com gigcalendar · CWE-89 | Yüksek7,5 | — | %2,0 | 24 Şub 2009 |
31İzleyin | CVE-2008-6653Kavram kanıtı | SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allowjoomla · joomla · CWE-89 | Yüksek7,5 | — | %2,0 | 7 Nis 2009 |
31İzleyin | CVE-2008-5208Kavram kanıtı | SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execjoomla · com datsogallery · CWE-89 | Yüksek7,5 | — | %2,0 | 24 Kas 2008 |
- CVE-2007-169943Planlayın
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (com_swmenupro and com_swmenufree) 4.0 component for Mambo and Joomla! allo
KritikCVSS 10,0Kavram kanıtıEPSS %11joomla · swmenu component26 Mar 2007
- CVE-2001-101141Planlayın
index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID
KritikCVSS 10,0İstismar yokEPSS %4mambo · mambo site server25 Tem 2001
- CVE-2003-124541Planlayın
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where session_id is set to the MD5 hash of
KritikCVSS 10,0Kavram kanıtıEPSS %4mambo · mambo site server31 Ara 2003
- CVE-2002-229041Planlayın
Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.
KritikCVSS 10,0İstismar yokEPSS %2mambo · mambo site server31 Ara 2002
- CVE-2006-426440Planlayın
Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers t
KritikCVSS 9,8İstismar yokEPSS %2mambo · mtg myhomepage component21 Ağu 2006
- CVE-2007-159639İzleyin
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo and Joomla! allow r
KritikCVSS 9,3Kavram kanıtıEPSS %8joomla · nfn address book22 Mar 2007
- CVE-2007-536238İzleyin
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and J
OrtaCVSS 6,8Kavram kanıtıEPSS %37mambo · mambo10 Eki 2007
- CVE-2007-420338İzleyin
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
KritikCVSS 9,3İstismar yokEPSS %2mambo · mambo open source7 Ağu 2007
- CVE-2005-415638İzleyin
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrar
KritikCVSS 9,4İstismar yokEPSS %2mambo · mambo open source 4.510 Ara 2005
- CVE-2008-290533İzleyin
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when registe
OrtaCVSS 6,8SilahlaştırılmışEPSS %18mambo · mambo30 Haz 2008
- CVE-2006-179432İzleyin
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,6Kavram kanıtıEPSS %6mambo · mambo17 Nis 2006
- CVE-2006-429631İzleyin
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers t
YüksekCVSS 7,5Kavram kanıtıEPSS %3mambo · bigape-backup component22 Ağu 2006
- CVE-2006-373631İzleyin
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attac
YüksekCVSS 7,5Kavram kanıtıEPSS %3mambo · videodb21 Tem 2006
- CVE-2004-169331İzleyin
PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modify
YüksekCVSS 7,5Kavram kanıtıEPSS %3mambo · mambo18 Eyl 2004
- CVE-2006-426931İzleyin
PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (com_x-shop) 1.7 and earlier for Mambo and Joomla! allow
YüksekCVSS 7,5İstismar yokEPSS %3joomla · x-shop component21 Ağu 2006
- CVE-2006-663431İzleyin
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote at
YüksekCVSS 7,5Kavram kanıtıEPSS %3mambo · extcalthai module18 Ara 2006
- CVE-2006-384331İzleyin
PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute ar
YüksekCVSS 7,5Kavram kanıtıEPSS %3mambo · mambo calendar25 Tem 2006
- CVE-2006-326231İzleyin
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary S
YüksekCVSS 7,5Kavram kanıtıEPSS %2mambo · mambo27 Haz 2006
- CVE-2007-445631İzleyin
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitr
YüksekCVSS 7,5Kavram kanıtıEPSS %2mambo · mambo21 Ağu 2007
- CVE-2006-710431İzleyin
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a compo
YüksekCVSS 7,5Kavram kanıtıEPSS %2mambo · mostlyce3 Mar 2007
- CVE-2008-299031İzleyin
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla!
YüksekCVSS 7,5Kavram kanıtıEPSS %2joomla · com facileforms2 Tem 2008
- CVE-2006-396231İzleyin
PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (c
YüksekCVSS 7,5Kavram kanıtıEPSS %2mambo · bayesiannaivefilter1 Ağu 2006
- CVE-2009-072631İzleyin
SQL injection vulnerability in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary
YüksekCVSS 7,5Kavram kanıtıEPSS %2gigcalendar · com gigcalendar24 Şub 2009
- CVE-2008-665331İzleyin
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joomla! and Mambo allow
YüksekCVSS 7,5Kavram kanıtıEPSS %2joomla · joomla7 Nis 2009
- CVE-2008-520831İzleyin
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to exec
YüksekCVSS 7,5Kavram kanıtıEPSS %2joomla · com datsogallery24 Kas 2008