Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mambo MEDIUM 6.8
CVE-2008-2905EPSS 18%

PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals…

No fix yet
Fix from $1,600 2008-06-30
Com Sermon HIGH 7.5
CVE-2008-0721

SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to execute arbitrary SQL commands…

No fix yet
Fix from $1,950 2008-02-12
Mambo Open Source MEDIUM 5.0
CVE-2008-0261

Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flo…

Patch available
Fix from $1,600 2008-01-15
Remository HIGH 7.5
CVE-2007-4505

SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers to execute arbitrary SQL comm…

No fix yet
Fix from $1,950 2007-08-23
Mambo HIGH 7.5
CVE-2007-4456

SQL injection vulnerability in index.php in the SimpleFAQ (com_simplefaq) 2.11 component for Mambo allows remote attackers to execute arbitrary SQL c…

No fix yet
Fix from $1,950 2007-08-21
Mambo Open Source HIGH 9.3
CVE-2007-4203

Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.

Mitigation only
Fix from $1,950 2007-08-08
Mambo Open Source HIGH 7.8
CVE-2006-7202

The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers t…

Patch available
Fix from $1,950 2007-05-09
Mambo Calendar MEDIUM 6.8
CVE-2007-2049

Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote attackers to execute arbitrary …

No fix yet
Fix from $1,600 2007-04-16
Flatmenu MEDIUM 6.8
CVE-2007-1702

PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote attackers to execute arbitrar…

Fix: after 1.7
Fix from $1,600 2007-03-27
Mambo Open Source HIGH 7.5
CVE-2006-7150

Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscom…

No fix yet
Fix from $1,950 2007-03-07
Mostlyce HIGH 7.5
CVE-2006-7104

PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for …

No fix yet
Fix from $1,950 2007-03-03
Mambo MEDIUM 6.8
CVE-2007-0789

SQL injection vulnerability in Mambo before 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in cancel edit fu…

Fix: after 4.5.4
Fix from $1,600 2007-02-06
Extcalthai Module HIGH 7.5
CVE-2006-6634

Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers t…

Fix: after 0.9.1
Fix from $1,950 2006-12-18
Contacts Xtd Component HIGH 7.5
CVE-2006-4375

PHP remote file inclusion vulnerability in contxtd.class.php in the Contacts XTD (ContXTD) component for Mambo (com_contxtd) allows remote attackers …

Mitigation only
Fix from $1,950 2006-08-26
Bigape Backup Component HIGH 7.5
CVE-2006-4296

PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include…

No fix yet
Fix from $1,950 2006-08-23
Mambo HIGH 7.5
CVE-2006-4286

PHP remote file inclusion vulnerability in contentpublisher.php in the contentpublisher component (com_contentpublisher) for Mambo allows remote atta…

Mitigation only
Fix from $1,950 2006-08-22
A6mambocredits Component MEDIUM 6.8
CVE-2006-4288EPSS 6%

PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo …

No fix yet
Fix from $1,600 2006-08-22
Catalogshop Component HIGH 7.5
CVE-2006-4275

PHP remote file inclusion vulnerability in catalogshop.php in the CatalogShop component for Mambo (com_catalogshop) allows remote attackers to execut…

Mitigation only
Fix from $1,950 2006-08-21
Anjel Component HIGH 7.5
CVE-2006-4280

PHP remote file inclusion vulnerability in anjel.index.php in ANJEL (formerly MaMML) Component (com_anjel) for Mambo allows remote attackers to execu…

Mitigation only
Fix from $1,950 2006-08-21
Mtg Myhomepage Component CRITICAL 9.8
CVE-2006-4264

Multiple PHP remote file inclusion vulnerabilities in the lmtg_myhomepage Component (com_lmtg_myhomepage) for Mambo allow remote attackers to execute…

Mitigation only
Fix from $2,300 2006-08-21
Mambelfish Component MEDIUM 6.8
CVE-2006-4270

PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote …

Fix: after 1.1
Fix from $1,600 2006-08-21
Mambo Gallery Manager HIGH 7.5
CVE-2006-3981

PHP remote file inclusion vulnerability in about.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to e…

Fix: after 0.95r2
Fix from $1,950 2006-08-05
Mambo Gallery Manager MEDIUM 6.8
CVE-2006-3980EPSS 6%

PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo …

Fix: after 0.95r2
Fix from $1,600 2006-08-05
Bayesiannaivefilter HIGH 7.5
CVE-2006-3962

PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (com_bayesi…

No fix yet
Fix from $1,950 2006-08-01
Mambatstaff MEDIUM 6.8
CVE-2006-3947

PHP remote file inclusion vulnerability in components/com_mambatstaff/mambatstaff.php in the Mambatstaff 3.1b and earlier component for Mambo allows …

Fix: after 3.1b
Fix from $1,600 2006-08-01
Artlinks Component MEDIUM 6.8
CVE-2006-3949

PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute…

No fix yet
Fix from $1,600 2006-08-01
Mambo Calendar HIGH 7.5
CVE-2006-3843

PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,950 2006-07-25
Mambo Multibanners MEDIUM 6.8
CVE-2006-3846

PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary P…

No fix yet
Fix from $1,600 2006-07-25
Smf Forum MEDIUM 6.8
CVE-2006-3773EPSS 6%

PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote att…

No fix yet
Fix from $1,600 2006-07-24
Videodb HIGH 7.5
CVE-2006-3736

PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to e…

No fix yet
Fix from $1,950 2006-07-21