CVE-2006-1794
Published Apr 17, 2006
Last updated 7 years ago
Overview
- Description
- SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.6
- Impact score
- 10
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Evaluator
- Comment
- -
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mambo:mambo:*:h:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B98DF901-844B-4073-948C-04B4ED32BE15", "versionEndIncluding": "4.5.3h" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.0.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BDF610B9-1105-4C37-B93E-4677311747F8" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5.1_1.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EAFE201B-A40F-4387-B855-5176A828BA58" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5.1a:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85B95AF0-CDD3-41FB-B343-46A69E909F68" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5.1a:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0AED1C3-740C-4EDE-A674-D753496A406A" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5.1a:beta_2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D7E78E2-1712-4B84-9EDD-58AF95AE6815" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68EE93EF-D273-4DEC-A85C-76290FEE40A6" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3AC21C1E-131A-4366-8741-7BE7594B6F59" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5.2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "993587DE-DA24-4D52-B190-AB236327D687" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5.2.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16ED2979-BB01-44E7-A0A3-D1B7F550F538" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5.3h:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2E4E3399-C743-4664-A55A-77BF543CBD42" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5_1.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49269426-5FA7-4CF1-AF64-BEC97A09E7E0" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5_1.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "863BE900-E43A-4E0E-BB25-A7403305F4EA" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5_1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AE971092-FF34-4F5C-A088-82914D46CE0B" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5_1.0.3_beta:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "953A9204-E94E-4756-A687-FBE781ACE158" }, { "criteria": "cpe:2.3:a:mambo:mambo:4.5_1.0.3_beta:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2DE8D25B-73E4-464F-8076-FC491B9F2861" } ], "operator": "OR" } ] } ]