CVE-2006-7150: SQL Injection
Published Mar 7, 2007
·Updated
Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) comcomment.php.
Affected Software
4 affected components
Mambo Mambo Open Source=4.6
Mambo Mambo Open Source=4.6-rc1
Mambo Mambo Open Source=4.6-rc2
Mambo Mambo Open Source=4.6.1
Event History
Mar 7, 2007
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7150?
CVE-2006-7150 has a high severity rating due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2006-7150?
To fix CVE-2006-7150, upgrade Mambo to version 4.6.2 or later, which addresses these vulnerabilities.
3
What software versions are affected by CVE-2006-7150?
CVE-2006-7150 affects Mambo 4.6, 4.6.1, and 4.6-rc1 and rc2 versions.
4
What are the consequences of exploiting CVE-2006-7150?
Exploiting CVE-2006-7150 allows attackers to execute arbitrary SQL commands, potentially compromising the database.
5
Who can be impacted by CVE-2006-7150?
Any website running vulnerable versions of Mambo is at risk of being impacted by CVE-2006-7150.