Mambo / Mambo Open Source
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2008-0261 | Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via un… | MEDIUM | 5.0 | Jan 15, 2008 |
| CVE-2007-4203 | Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter. | HIGH | 9.3 | Aug 8, 2007 |
| CVE-2006-7202 | The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers to read cer… | HIGH | 7.8 | May 9, 2007 |
| CVE-2006-7150 | Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php a… | HIGH | 7.5 | Mar 7, 2007 |
| CVE-2004-2072 | Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on ot… | MEDIUM | 6.8 | May 19, 2005 |
| CVE-2004-1825 | Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to inject arbitrary web script… | MEDIUM | 4.3 | May 10, 2005 |
| CVE-2004-1692 | Cross-site scripting (XSS) vulnerability in index.php in Mambo 4.5 (1.0.9) allows remote attackers to inject arbitrary web script or HTML via the (1) Itemid, (… | MEDIUM | 4.3 | Feb 20, 2005 |
Showing 1 to 7 of 7 CVEs