Show filters
76 Total Results
Displaying 31-40 of 76
Sort by:
Attacker Value
Unknown

CVE-2007-4456

Disclosure Date: August 21, 2007 (last updated October 04, 2023)
SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL commands via the aid parameter. NOTE: it was later reported that 2.40 is also affected, and that the component can be used in Joomla! in addition to Mambo.
0
Attacker Value
Unknown

CVE-2007-4203

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
0
Attacker Value
Unknown

CVE-2007-2557

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
MOStlyDB Admin in Mambo 4.6.1 does not properly check privileges, which allows remote authenticated administrators to have an unknown impact via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2006-7202

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers to read certain content via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-2317

Disclosure Date: April 26, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and probably other products, allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to bb_plugins.php in (1) components/minibb/ or (2) components/com_minibb, or (3) configuration.php. NOTE: the com_minibb.php vector is already covered by CVE-2006-3690.
0
Attacker Value
Unknown

CVE-2007-2049

Disclosure Date: April 16, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) com_calendar.php or (2) mod_calendar.php.
0
Attacker Value
Unknown

CVE-2006-7149

Disclosure Date: March 07, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the query string to (a) index.php, which reflects the string in an error message from mod_login.php; and the (2) mcname parameter to (b) moscomment.php and (c) com_comment.php.
0
Attacker Value
Unknown

CVE-2006-7150

Disclosure Date: March 07, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) com_comment.php.
0
Attacker Value
Unknown

CVE-2007-0789

Disclosure Date: February 06, 2007 (last updated October 04, 2023)
SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit functions, possibly related to the id parameter.
0
Attacker Value
Unknown

CVE-2007-0374

Disclosure Date: January 19, 2007 (last updated October 04, 2023)
SQL injection vulnerability in (1) Joomla! 1.0.11 and 1.5 Beta, and (2) Mambo 4.6.1, allows remote attackers to execute arbitrary SQL commands via the id parameter when cancelling content editing.
0