VYPR

Mambo Open Source 4.5

Sign in to watch

by Mambo (software)

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2004-18260.030.01Mar 16, 2004SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2005-41560.000.01Dec 11, 2005Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magic_quotes_gpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character.