Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-1794


SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).


Published

2006-04-17T10:02:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.6 (HIGH)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

4.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mambo mambo ≤ 4.5.3h Yes
Application mambo mambo 4.0.14 Yes
Application mambo mambo 4.5.1_1.0.9 Yes
Application mambo mambo 4.5.1a Yes
Application mambo mambo 4.5.1a Yes
Application mambo mambo 4.5.1a Yes
Application mambo mambo 4.5.2 Yes
Application mambo mambo 4.5.2.1 Yes
Application mambo mambo 4.5.2.2 Yes
Application mambo mambo 4.5.2.3 Yes
Application mambo mambo 4.5.3h Yes
Application mambo mambo 4.5_1.0.0 Yes
Application mambo mambo 4.5_1.0.1 Yes
Application mambo mambo 4.5_1.0.2 Yes
Application mambo mambo 4.5_1.0.3_beta Yes
Application mambo mambo 4.5_1.0.3_beta Yes

References