Vulnerabilities > Mambo > High

DATE CVE VULNERABILITY TITLE RISK
2008-02-04 CVE-2008-0561 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
network
low complexity
arthur-konze-webdesign joomla mambo CWE-89
7.5
2008-01-31 CVE-2008-0519 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a CatView action.
network
low complexity
joomla mambo CWE-89
7.5
2008-01-31 CVE-2008-0518 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
network
low complexity
joomla mambo CWE-89
7.5
2008-01-31 CVE-2008-0517 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.
network
low complexity
darko-selesi joomla mambo CWE-89
7.5
2008-01-31 CVE-2008-0515 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the musepoes (com_musepoes) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an answer action.
network
low complexity
joomla mambo CWE-89
7.5
2008-01-31 CVE-2008-0514 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action.
network
low complexity
joomla mambo CWE-89
7.5
2008-01-31 CVE-2008-0511 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the MaMML (com_mamml) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.
network
low complexity
joomla mambo CWE-89
7.5
2008-01-31 CVE-2008-0510 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the Newsletter (com_newsletter) component for Mambo 4.5 and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter.
network
low complexity
joomla mambo CWE-89
7.5
2007-10-03 CVE-2007-5177 SQL Injection vulnerability in multiple products
SQL injection vulnerability in index.php in the MambAds (com_mambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid parameter.
network
low complexity
mambads mambo CWE-89
7.5
2007-08-23 CVE-2007-4505 SQL-Injection vulnerability in Mambo
SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat action.
network
low complexity
mambo mamboserver
7.5