First published: Tue Jun 27 2006(Updated: )
SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mambo (MamboCMS) | <=4.6 | |
Mambo | <=4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3263 has a medium severity rating due to its potential for SQL injection attacks.
To fix CVE-2006-3263, update Mambo to the latest version that is not affected by this vulnerability.
Mambo versions 4.6rc1 and earlier are affected by CVE-2006-3263.
CVE-2006-3263 is an SQL injection vulnerability that allows the execution of arbitrary SQL commands.
Yes, CVE-2006-3263 can be exploited remotely by attackers through the catid parameter.