Vulnerability index

Browse CVEs

26 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mambo MEDIUM 6.8
CVE-2008-2905EPSS 18%

PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals…

No fix yet
Fix from $1,600 2008-06-30
Com Sermon HIGH 7.5
CVE-2008-0721

SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to execute arbitrary SQL commands…

No fix yet
Fix from $1,950 2008-02-12
Remository HIGH 7.5
CVE-2007-4505

SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers to execute arbitrary SQL comm…

No fix yet
Fix from $1,950 2007-08-23
Mambo HIGH 7.5
CVE-2007-4456

SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL c…

No fix yet
Fix from $1,950 2007-08-21
Mambo Open Source HIGH 9.3
CVE-2007-4203

Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.

Mitigation only
Fix from $1,950 2007-08-08
Mambo Calendar MEDIUM 6.8
CVE-2007-2049

Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary …

No fix yet
Fix from $1,600 2007-04-16
Mambo Open Source HIGH 7.5
CVE-2006-7150

Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscom…

No fix yet
Fix from $1,950 2007-03-07
Mostlyce HIGH 7.5
CVE-2006-7104

PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for …

No fix yet
Fix from $1,950 2007-03-03
Contacts Xtd Component HIGH 7.5
CVE-2006-4375

PHP remote file inclusion vulnerability in contxtd.class.php in the Contacts XTD (ContXTD) component for Mambo (com_contxtd) allows remote attackers …

Mitigation only
Fix from $1,950 2006-08-26
Bigape Backup Component HIGH 7.5
CVE-2006-4296

PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include…

No fix yet
Fix from $1,950 2006-08-23
Mambo HIGH 7.5
CVE-2006-4286

PHP remote file inclusion vulnerability in contentpublisher.php in the contentpublisher component (com_contentpublisher) for Mambo allows remote atta…

Mitigation only
Fix from $1,950 2006-08-22
A6mambocredits Component MEDIUM 6.8
CVE-2006-4288EPSS 6%

PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo …

No fix yet
Fix from $1,600 2006-08-22
Catalogshop Component HIGH 7.5
CVE-2006-4275

PHP remote file inclusion vulnerability in catalogshop.php in the CatalogShop component for Mambo (com_catalogshop) allows remote attackers to execut…

Mitigation only
Fix from $1,950 2006-08-21
Anjel Component HIGH 7.5
CVE-2006-4280

PHP remote file inclusion vulnerability in anjel.index.php in ANJEL (formerly MaMML) Component (com_anjel) for Mambo allows remote attackers to execu…

Mitigation only
Fix from $1,950 2006-08-21
Mtg Myhomepage Component CRITICAL 9.8
CVE-2006-4264

Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers to execute…

Mitigation only
Fix from $2,300 2006-08-21
Bayesiannaivefilter HIGH 7.5
CVE-2006-3962

PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (com_bayesi…

No fix yet
Fix from $1,950 2006-08-01
Artlinks Component MEDIUM 6.8
CVE-2006-3949

PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute…

No fix yet
Fix from $1,600 2006-08-01
Mambo Calendar HIGH 7.5
CVE-2006-3843

PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,950 2006-07-25
Mambo Multibanners MEDIUM 6.8
CVE-2006-3846

PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,600 2006-07-25
Smf Forum MEDIUM 6.8
CVE-2006-3773EPSS 6%

PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote att…

No fix yet
Fix from $1,600 2006-07-24
Videodb HIGH 7.5
CVE-2006-3736

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to e…

No fix yet
Fix from $1,950 2006-07-21
Sitemap MEDIUM 6.8
CVE-2006-3749

PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS, when register_globals is ena…

No fix yet
Fix from $1,600 2006-07-21
Mambo Open Source 4.5 HIGH 9.4
CVE-2005-4156

Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files a…

Mitigation only
Fix from $1,950 2005-12-11
Mambo MEDIUM 5.0
CVE-2005-3586

content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the appli…

No fix yet
Fix from $1,600 2005-11-16
Mambo Open Source MEDIUM 6.8
CVE-2004-2072

Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute sc…

No fix yet
Fix from $1,600 2004-12-31
Mambo Site Server HIGH 10.0
CVE-2002-2290

Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.

Mitigation only
Fix from $1,950 2002-12-31