CVE-2006-7149: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the query string to (a) index.php, which reflects the string in an error message from modlogin.php; and the (2) mcname parameter to (b) moscomment.php and (c) comcomment.php.
Affected Software
Event History
Frequently Asked Questions
What are the vulnerabilities associated with CVE-2006-7149?
CVE-2006-7149 is related to multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x that allow remote attackers to inject arbitrary web script or HTML.
What versions of Mambo are affected by CVE-2006-7149?
The affected versions are Mambo 4.6-rc1, 4.6-rc2, and 4.6.1.
What is the impact of CVE-2006-7149 on web applications?
Web applications using Mambo 4.6.x are vulnerable to XSS attacks, potentially allowing attackers to execute malicious scripts in users' browsers.
How can I protect my application from CVE-2006-7149?
To protect your application, you should upgrade to a fixed version of Mambo that addresses the XSS vulnerabilities.
What kind of attack can be executed through CVE-2006-7149?
Attackers can execute XSS attacks that may lead to session hijacking, phishing, or other malicious activities affecting users.