Vulnerabilities > Mambo > Mambo Open Source 4 5

DATE CVE VULNERABILITY TITLE RISK
2005-12-11 CVE-2005-4156 Denial-Of-Service vulnerability in Mambo Open Source 4.5
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character.
network
low complexity
mambo
critical
9.4
2004-03-16 CVE-2004-1826 SQL Injection vulnerability in Mambo Open Source
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
mambo
7.5