Skip to main content

Vendor archive

mamboxchange CVEs

Beta · best-effort

15 CVEs tagged to vendor mamboxchange1 Critical, 9 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2008-0499

Published Jan 30, 2008

SQL injection vulnerability in Mambo LaiThai 4.5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0500

Published Jan 30, 2008

Multiple unspecified vulnerabilities in Mambo LaiThai 4.5.5 have unknown impact and attack vectors related to (1) mod_login and (2) mod_template_chooser.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1992

Published Apr 12, 2007

Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7092

Published Mar 2, 2007

SQL injection vulnerability in includes/mambo.php in Mambo LaiThai 4.5.4 SP2 and earlier allows remote attackers to execute arbitrary SQL commands via the usercookie[password] coo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7093

Published Mar 2, 2007

Cross-site scripting (XSS) vulnerability in Mambo LaiThai 4.5.4 Security Patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6051

Published Nov 22, 2006

PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5254

Published Oct 12, 2006

PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), aka regdetailed, 4.1 and earlie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4858

Published Sep 19, 2006

PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbit…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4282

Published Aug 22, 2006

PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows remote attackers to execute arb…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4241

Published Aug 21, 2006

PHP remote file inclusion vulnerability in processor/reporter.sql.php in the Reporter Mambo component (com_reporter) allows remote attackers to execute arbitrary PHP code via a UR…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4195

Published Aug 17, 2006

PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4203

Published Aug 17, 2006

PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3930

Published Jul 31, 2006

PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to execute arbitrary PHP code via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3748

Published Jul 21, 2006

PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attacke…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3528

Published Jul 12, 2006

Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the sbp paramete…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1