Vulnerabilities (CVE)

Filtered by vendor Mambo Subscribe
Filtered by product Mambo Open Source 4.5
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4156 1 Mambo 1 Mambo Open Source 4.5 2024-02-04 9.4 HIGH N/A
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character.
CVE-2004-1826 1 Mambo 1 Mambo Open Source 4.5 2024-02-04 7.5 HIGH N/A
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.