VendorsMambomambo_open_source4.6.1
Vulnerabilities

Mambo Mambo Open Source 4.6.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2006-7202
The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers to read certain content via unspecified vectors.
Published 2007-05-09 · Modified
7.8EPSS 0.014
CVE-2006-7150
Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) com_comment.php.
Published 2007-03-07 · Modified
7.5EPSS 0.012