Show filters
76 Total Results
Displaying 51-60 of 76
Sort by:
Attacker Value
Unknown
CVE-2006-3396
Disclosure Date: July 06, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2006-3340
Disclosure Date: July 03, 2006 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the (1) phpbb_root_path parameter in (a) includes/functions_cms.php and the (2) GlobalSettings[templatesDirectory] parameter in multiple files in the "includes" directory including (b) adminSensored.php, (c) adminBoards.php, (d) adminAttachments.php, (e) adminAvatars.php, (f) adminBackupdatabase.php, (g) adminBanned.php, (h) adminForums.php, (i) adminPolls.php, (j) adminSmileys.php, (k) poll.php, and (l) move.php.
0
Attacker Value
Unknown
CVE-2006-3294
Disclosure Date: June 29, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in mod_cbsms_messages.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
0
Attacker Value
Unknown
CVE-2006-3302
Disclosure Date: June 29, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in mod_cbsms.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosC_a_path parameter. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2006-3263
Disclosure Date: June 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
0
Attacker Value
Unknown
CVE-2006-3262
Disclosure Date: June 27, 2006 (last updated October 04, 2023)
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.
0
Attacker Value
Unknown
CVE-2006-1957
Disclosure Date: April 21, 2006 (last updated October 04, 2023)
The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to cause a denial of service (disk consumption and possibly web-server outage) via multiple requests with different values of the feed parameter.
0
Attacker Value
Unknown
CVE-2006-1956
Disclosure Date: April 21, 2006 (last updated October 04, 2023)
The com_rss option (rss.php) in (1) Mambo and (2) Joomla! allows remote attackers to obtain sensitive information via an invalid feed parameter, which reveals the path in an error message.
0
Attacker Value
Unknown
CVE-2006-1794
Disclosure Date: April 17, 2006 (last updated October 04, 2023)
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).
0
Attacker Value
Unknown
CVE-2006-0871
Disclosure Date: February 24, 2006 (last updated February 22, 2025)
Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.
0