7.5
CVSSv2

CVE-2004-1826

Published: 16/03/2004 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and previous versions allows remote malicious users to execute arbitrary SQL commands via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

mambo mambo open source 4.5 1.0.0

mambo mambo open source 4.5 1.0.3

mambo mambo open source 4.5 1.0.3beta

mambo mambo open source 4.5 1.0.1

mambo mambo open source 4.5 1.0.2

Exploits

source: wwwsecurityfocuscom/bid/9891/info It has been reported that the Mambo 'indexphp' script is prone to an SQL injection vulnerability This issue is due to a failure of the application to properly validate user supplied URI input As a result of this a malicious user may influence database queries in order to view or modify sensiti ...