Vulnerabilities > Mambo > Mostlyce

DATE CVE VULNERABILITY TITLE RISK
2008-05-29 CVE-2008-2500 Cross-Site Scripting vulnerability in Mambo Mostlyce
Cross-site scripting (XSS) vulnerability in the MOStlyContent Editor (MOStlyCE) component before 3.0 for Mambo allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
mambo CWE-79
4.3
2007-03-03 CVE-2006-7104 Code Injection vulnerability in Mambo Mostlyce 4.5.4
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
network
low complexity
mambo CWE-94
7.5