Show filters
144 Total Results
Displaying 1-10 of 144
Sort by:
Attacker Value
Unknown
CVE-2011-2499
Disclosure Date: February 12, 2020 (last updated November 28, 2024)
Mambo CMS through 4.6.5 has multiple XSS.
0
Attacker Value
Unknown
CVE-2013-2565
Disclosure Date: February 15, 2019 (last updated November 27, 2024)
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
0
Attacker Value
Unknown
CVE-2013-2563
Disclosure Date: June 09, 2014 (last updated October 05, 2023)
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.
0
Attacker Value
Unknown
CVE-2013-2564
Disclosure Date: June 09, 2014 (last updated October 05, 2023)
Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.
0
Attacker Value
Unknown
CVE-2013-2562
Disclosure Date: June 09, 2014 (last updated October 05, 2023)
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-2917
Disclosure Date: December 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter.
0
Attacker Value
Unknown
CVE-2011-3754
Disclosure Date: September 23, 2011 (last updated October 04, 2023)
Mambo 4.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/sef.php and certain other files.
0
Attacker Value
Unknown
CVE-2009-4199
Disclosure Date: December 04, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php.
0
Attacker Value
Unknown
CVE-2008-7213
Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML via the Command parameter.
0
Attacker Value
Unknown
CVE-2008-7212
Disclosure Date: September 11, 2009 (last updated October 04, 2023)
MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php, which reveals the installation path in an error message.
0