CVE-2006-1794
published 2006-04-17CVE-2006-1794: SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the…
PriorityP344high7.6CVSS 2.0
AVNACHAuNCCICAC
EXPLOIT
EPSS
5.53%
91.8th percentile
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mambo | mambo | <= 4.5.3h | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
| mambo | mambo | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v96v-x3w6-88vq: SQL injection vulnerability in Mambo 4
ghsa_unreviewed·2022-05-01
CVE-2006-1794 [HIGH] GHSA-v96v-x3w6-88vq: SQL injection vulnerability in Mambo 4
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).
GHSA
GHSA-wmxw-xmgw-6xh3: Directory traversal vulnerability in the _setTemplate function in Mambo 4
ghsa_unreviewed·2022-05-01·CVSS 7.6
CVE-2006-0871 [HIGH] CWE-22 GHSA-wmxw-xmgw-6xh3: Directory traversal vulnerability in the _setTemplate function in Mambo 4
Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.
No detection rules found.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.htmlhttp://secunia.com/advisories/18935http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/http://www.gulftech.org/?node=research&article_id=00104-02242006http://www.osvdb.org/23402http://www.osvdb.org/23503http://www.securityfocus.com/bid/16775http://www.vupen.com/english/advisories/2006/0719https://exchange.xforce.ibmcloud.com/vulnerabilities/24951http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.htmlhttp://secunia.com/advisories/18935http://source.mambo-foundation.org/view/news/Announcements/Security_Patch_Released/http://www.gulftech.org/?node=research&article_id=00104-02242006http://www.osvdb.org/23402http://www.osvdb.org/23503http://www.securityfocus.com/bid/16775http://www.vupen.com/english/advisories/2006/0719https://exchange.xforce.ibmcloud.com/vulnerabilities/24951
2006-04-17
Published