Vulnerabilities > Mamboxchange > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-09-19 | CVE-2006-4858 | Code Injection vulnerability in Mamboxchange Serverstat Component PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | 6.8 |
2006-08-17 | CVE-2006-4195 | Code Injection vulnerability in Mamboxchange Peoplebook 1.0 PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals and allow_url_fopen are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | 6.8 |
2006-07-21 | CVE-2006-3748 | Code Injection vulnerability in Mamboxchange Loudmouth 4.0J PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | 6.8 |
2006-07-12 | CVE-2006-3528 | Code Injection vulnerability in Mamboxchange Simpleboard Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) image_upload.php and (2) file_upload.php. | 6.8 |