See how mambads compares to other vendors in security performance
SQL injection vulnerability in the MambAds (commambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the macat parameter in a view action to index.php, a different vector than CVE-2007-5177.
SQL injection vulnerability in index.php in the MambAds (commambads) 1.5 and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the caid parameter.