Mambo
mambo
107 CVEs • 65 products
Products (65)
Click to collapseToggle
Products (65)
Click to collapse
CVEs (107)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view action to index.php, a di...Show more |
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to mambots/editors/mo...Show more |
2Joomla Mambo3Com Facileforms Com FacileformsJoomlaApr 23, 2026 Jul 2, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the ff_compat...Show more |
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via...Show more |
Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor (MOStlyCE) component before 3.0 for Mambo allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
3Joomla MamboPage Flip Tools3Com Flippingbook Com FlippingbookFlipping BookApr 23, 2026 May 6, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter. |
3Joomla JoomlapolisMambo3Com Comprofiler Com ComprofilerCommunity BuilderApr 23, 2026 May 6, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action...Show more |
2Joomla Mambo2Datsogallery DatsogalleryApr 23, 2026 Mar 28, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the Datsogallery (com_datsogallery) 1.3.1 module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE:...Show more |
3Ewriting JoomlaMambo3Com Ewriting Com EwritingEwritingApr 23, 2026 Mar 12, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action. |
2Joomla Mambo2Com Garyscookbook Com GaryscookbookApr 23, 2026 Mar 4, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to...Show more |
2Joomla Mambo2Com Facileforms Com FacileformsApr 23, 2026 Feb 21, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. |
2Joomla Mambo2Com Salesrep Com SalesrepApr 23, 2026 Feb 21, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php. |
SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: this issue might be site-specific. If so,...Show more |
2Joomla Mambo2Com Downloads Com DownloadsApr 23, 2026 Feb 21, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat function, a differe...Show more |
SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter. |
2Joomla Mambo2Com Ricette Component Com Ricette ComponentApr 23, 2026 Feb 20, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter. |
2Joomla Mambo2Kemas Antonius Com Quran Kemas Antonius Com QuranApr 23, 2026 Feb 20, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the surano parameter in a viewayat ac...Show more |
3Joomla JoomlapixelMambo3Jooget JoomlaMamboApr 23, 2026 Feb 19, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail task. |
2Joomla Mambo2Com Filebase Component Com Filebase ComponentApr 23, 2026 Feb 19, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action. |
2Joomla Mambo2Com Scheduling Component Com Scheduling ComponentApr 23, 2026 Feb 19, 2008 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in the com_scheduling module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter. |