Security Advisory

CVE-2006-1794

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2006-04-17 10:00:00
Last updated 2024-08-07 17:27:28
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).