Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mambo Cms MEDIUM 6.1
CVE-2011-2499

Mambo CMS through 4.6.5 has multiple XSS.

Fix: after 4.6.5
Fix from $1,600 2020-02-12
Mambo Cms MEDIUM 5.3
CVE-2013-2565

A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the…

No fix yet
Fix from $1,600 2019-02-15
Mambo Cms MEDIUM 5.0
CVE-2013-2564

Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file.

No fix yet
Fix from $1,600 2014-06-09
Mambo HIGH 7.5
CVE-2011-2917

SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via …

Fix: after 4.6.5
Fix from $1,950 2011-12-08
Mambo MEDIUM 5.0
CVE-2011-3754

Mambo 4.6.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an er…

No fix yet
Fix from $1,600 2011-09-23
Mambo MEDIUM 6.8
CVE-2008-7214

Cross-site request forgery (CSRF) vulnerability in administrator/index2.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote…

Fix: after 4.6.3
Fix from $1,600 2009-09-11
Mambo MEDIUM 5.8
CVE-2008-7215

The Image Manager in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to rename arbitrary files and cause a denial of…

Fix: after 4.6.3
Fix from $1,600 2009-09-11
Mambo MEDIUM 5.0
CVE-2008-7212

MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/edit…

Fix: after 4.6.3
Fix from $1,600 2009-09-11
Mambo HIGH 7.5
CVE-2008-2498

Multiple SQL injection vulnerabilities in index.php in Mambo before 4.6.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbit…

Fix: after 4.6.4
Fix from $1,950 2008-05-28
Mambo MEDIUM 5.0
CVE-2008-2497

CRLF injection vulnerability in Mambo before 4.6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attac…

Fix: after 4.6.4
Fix from $1,600 2008-05-28