CVE Database
/

CVE-2006-1794

Back to search

CVE-2006-1794

Published: Apr 17, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).

VendorProductVersions

n/a

n/a

affected
n/a

References

18935
third-party-advisory
x_refsource_SECUNIA
23402
vdb-entry
x_refsource_OSVDB
ADV-2006-0719
vdb-entry
x_refsource_VUPEN
20060224 Mambo Multiple Vulnerabilities
mailing-list
x_refsource_BUGTRAQ
16775
vdb-entry
x_refsource_BID
mambo-index2-sql-injection(24951)
vdb-entry
x_refsource_XF
23503
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now