Show filters
76 Total Results
Displaying 21-30 of 76
Sort by:
Attacker Value
Unknown

CVE-2008-0562

Disclosure Date: February 04, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
0
Attacker Value
Unknown

CVE-2008-0517

Disclosure Date: January 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.
0
Attacker Value
Unknown

CVE-2008-0510

Disclosure Date: January 31, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.
0
Attacker Value
Unknown

CVE-2008-0261

Disclosure Date: January 15, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-6455

Disclosure Date: December 20, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Itemid parameter in a com_frontpage option and the (2) option parameter.
0
Attacker Value
Unknown

CVE-2007-5362

Disclosure Date: October 11, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia Lite (com_mosmedia) 4.5.1 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) credits.html.php, (2) info.html.php, (3) media.divs.php, (4) media.divs.js.php, (5) purchase.html.php, or (6) support.html.php in includes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: vector 3 may be the same as CVE-2007-2043.2.
0
Attacker Value
Unknown

CVE-2007-5177

Disclosure Date: October 03, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the MambAds (com_mambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid parameter.
0
Attacker Value
Unknown

CVE-2007-4745

Disclosure Date: September 06, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the AkoBook 3.42 and earlier component (com_akobook) for Mambo allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) gbmail and (2) gbpage parameters in the sign function.
0
Attacker Value
Unknown

CVE-2007-4505

Disclosure Date: August 23, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.
0
Attacker Value
Unknown

CVE-2007-4456

Disclosure Date: August 21, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.
0