Filtered by vendor Mambo-foundation
Subscriptions
Total
26 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2010-4944 | 2 Joomla, Mambo-foundation | 3 Com Elite Experts, Joomla\!, Mambo | 2024-08-07 | N/A |
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showExpertProfileDetailed action to index.php. | ||||
CVE-2011-2499 | 1 Mambo-foundation | 1 Mambo Cms | 2024-08-06 | 6.1 Medium |
Mambo CMS through 4.6.5 has multiple XSS. | ||||
CVE-2013-2564 | 1 Mambo-foundation | 1 Mambo Cms | 2024-08-06 | N/A |
Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a crafted file. | ||||
CVE-2013-2565 | 1 Mambo-foundation | 1 Mambo Cms | 2024-08-06 | N/A |
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver. | ||||
CVE-2013-2562 | 1 Mambo-foundation | 1 Mambo Cms | 2024-08-06 | N/A |
Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors. | ||||
CVE-2013-2563 | 1 Mambo-foundation | 1 Mambo Cms | 2024-08-06 | N/A |
Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin password hash by reading the file. |