7.6
CVSSv2

CVE-2006-1794

Published: 17/04/2006 Updated: 20/07/2017
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 765
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote malicious users to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).

Vulnerable Product Search on Vulmon Subscribe to Product

mambo mambo 4.0.14

mambo mambo 4.5.2.3

mambo mambo 4.5.3h

mambo mambo 4.5.1_1.0.9

mambo mambo 4.5.1a

mambo mambo 4.5_1.0.0

mambo mambo 4.5_1.0.1

mambo mambo 4.5.2.1

mambo mambo 4.5.2.2

mambo mambo 4.5_1.0.3_beta

mambo mambo

mambo mambo 4.5.2

mambo mambo 4.5_1.0.2

Exploits

Mambo Multiple Vulnerabilities Vendor: Miro International Pty Ltd Product: Mambo Version: <= 453h Website: wwwmamboservercom BID: 16775 CVE: CVE-2006-0871 CVE-2006-1794 OSVDB: 23402 23503 23505 SECUNIA: 18935 PACKETSTORM: 44191 Description: Mambo is a popular Open Source Content Management System released under the GNU General ...