Vulnerabilities > Mambo > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-02-21 | CVE-2008-0853 | SQL Injection vulnerability in multiple products SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | 7.5 |
2008-02-21 | CVE-2008-0849 | SQL Injection vulnerability in multiple products SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat function, a different vector than CVE-2008-0652. | 7.5 |
2008-02-20 | CVE-2008-0846 | SQL Injection vulnerability in multiple products SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter. | 7.5 |
2008-02-20 | CVE-2008-0841 | SQL Injection vulnerability in multiple products SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2008-02-20 | CVE-2008-0832 | SQL Injection vulnerability in multiple products SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the surano parameter in a viewayat action. | 7.5 |
2008-02-19 | CVE-2008-0829 | SQL Injection vulnerability in multiple products SQL injection vulnerability in jooget.php in the Joomlapixel Jooget! (com_jooget) 2.6.8 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail task. | 7.5 |
2008-02-19 | CVE-2008-0817 | SQL Injection vulnerability in multiple products SQL injection vulnerability in the com_filebase component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action. | 7.5 |
2008-02-19 | CVE-2008-0810 | SQL Injection vulnerability in multiple products SQL injection vulnerability in the com_scheduling module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter. | 7.5 |
2008-02-15 | CVE-2008-0799 | SQL Injection vulnerability in multiple products SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the tid parameter in a user_tst_shw action. | 7.5 |
2008-02-15 | CVE-2008-0795 | SQL Injection vulnerability in multiple products SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action. | 7.5 |