Vulnerabilities > Mambo

DATE CVE VULNERABILITY TITLE RISK
2008-02-20 CVE-2008-0832 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the surano parameter in a viewayat action.
network
low complexity
joomla mambo CWE-89
7.5
2008-02-19 CVE-2008-0829 SQL Injection vulnerability in multiple products
SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail task.
network
low complexity
joomla joomlapixel mambo CWE-89
7.5
2008-02-19 CVE-2008-0817 SQL Injection vulnerability in multiple products
SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.
network
low complexity
joomla mambo CWE-89
7.5
2008-02-19 CVE-2008-0810 SQL Injection vulnerability in multiple products
SQL injection vulnerability in the com_scheduling module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
joomla mambo CWE-89
7.5
2008-02-15 CVE-2008-0799 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action.
network
low complexity
joomla mambo CWE-89
7.5
2008-02-15 CVE-2008-0795 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.
network
low complexity
joomla mambo mgfi CWE-89
7.5
2008-02-14 CVE-2008-0773 SQL Injection vulnerability in multiple products
SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
joomla mambo phil-taylor CWE-89
7.5
2008-02-14 CVE-2008-0772 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task.
network
low complexity
joomla mambo CWE-89
7.5
2008-02-13 CVE-2008-0752 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action.
network
low complexity
joomla mambo CWE-89
7.5
2008-02-13 CVE-2008-0746 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
network
low complexity
joomla mambo CWE-89
7.5