Show filters
144 Total Results
Displaying 1-10 of 144
Sort by:
Attacker Value
Unknown

CVE-2011-2499

Disclosure Date: February 12, 2020 (last updated November 28, 2024)
Mambo CMS through 4.6.5 has multiple XSS.
Attacker Value
Unknown

CVE-2013-2565

Disclosure Date: February 15, 2019 (last updated November 27, 2024)
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
0
Attacker Value
Unknown

CVE-2013-2563

Disclosure Date: June 09, 2014 (last updated October 05, 2023)
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file.
0
Attacker Value
Unknown

CVE-2013-2564

Disclosure Date: June 09, 2014 (last updated October 05, 2023)
Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.
0
Attacker Value
Unknown

CVE-2013-2562

Disclosure Date: June 09, 2014 (last updated October 05, 2023)
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-2917

Disclosure Date: December 08, 2011 (last updated October 04, 2023)
SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter.
0
Attacker Value
Unknown

CVE-2011-3754

Disclosure Date: September 23, 2011 (last updated October 04, 2023)
Mambo 4.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by includes/sef.php and certain other files.
0
Attacker Value
Unknown

CVE-2009-4199

Disclosure Date: December 04, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php.
0
Attacker Value
Unknown

CVE-2008-7213

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML via the Command parameter.
0
Attacker Value
Unknown

CVE-2008-7212

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php, which reveals the installation path in an error message.
0