Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.8 CVE-2006-3749 PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS, when register_globals is ena… Sitemap No fix yet Fix from $1,6002006-07-21 HIGH 7.5 CVE-2006-3262 SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL comman… Mambo after 4.6 Fix from $1,9502006-06-27 HIGH 7.5 CVE-2006-3263 SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL comman… Mambo after 4.6 Fix from $1,9502006-06-27 HIGH 7.6 CVE-2006-1794EPSS 6% SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) t… Mambo after 4.5.3h Fix from $1,9502006-04-17 MEDIUM 6.4 CVE-2006-0871 Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read … Mambo Patch available Fix from $1,6002006-02-24 HIGH 9.4 CVE-2005-4156 Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files a… Mambo Open Source 4.5 Mitigation only Fix from $1,9502005-12-11 MEDIUM 5.0 CVE-2005-3586 content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the appli… Mambo No fix yet Fix from $1,6002005-11-16 HIGH 7.5 CVE-2005-2002 SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating… Mambo Patch available Fix from $1,9502005-06-15 HIGH 7.5 CVE-2005-0512 PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_ab… Mambo after 4.5.2 Fix from $1,9502005-02-21 HIGH 7.5 CVE-2004-2143 SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitr… Mambo Portal after 4.5.1_1.0.9 Fix from $1,9502004-12-31 MEDIUM 6.8 CVE-2004-2072 Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute sc… Mambo Open Source No fix yet Fix from $1,6002004-12-31 HIGH 7.5 CVE-2004-1693 PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the m… Mambo Patch available Fix from $1,9502004-09-18 HIGH 7.5 CVE-2004-1826 SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands … Mambo Open Source 4.5 Patch available Fix from $1,9502004-03-16 HIGH 10.0 CVE-2002-2290 Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges. Mambo Site Server Mitigation only Fix from $1,9502002-12-31 MEDIUM 6.8 CVE-2002-1662 Multiple cross-site scripting (XSS) vulnerabilities in Mambo Site Server 4.0.11 allow remote attackers to execute arbitrary script on other clients v… Mambo Site Server Patch available Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2247 The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information such as the full web root pa… Mambo Site Server Patch available Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2288 Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.php with a parameter that doe… Site Server Patch available Fix from $1,6002002-12-31 HIGH 10.0 CVE-2001-1011 index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter… Mambo Site Server Patch available Fix from $1,9502001-07-25