See how mambo compares to other vendors in security performance
index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.
index2.php in Mambo 4.0.12 allows remote attackers to gain administrator access via a URL request where sessionid is set to the MD5 hash of a session cookie.
Mambo Site Server 4.0.11 installs with a default username and password of admin, which allows remote attackers to gain privileges.
Multiple PHP remote file inclusion vulnerabilities in the SWmenu (comswmenupro and comswmenufree) 4.0 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter to ImageManager/Classes/ImageManager.php under the (1) components/ or (2) administrator/components/ directory trees.
DISPUTED Multiple PHP remote file inclusion vulnerabilities in the lmtgmyhomepage Component (comlmtgmyhomepage) for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter in (1) install.lmtghomepage.php and (2) mtghomepage.php. NOTE: this issue has been disputed by a third party, who states that the $mosConfigabsolutepath variable is only used within a function definition. CVE source code analysis on 20060824 is not conclusive but tends to concur with the dispute. In addition, it appears that the component name is actually "lmtgmyhomepage".
Unspecified vulnerability in Mambo 4.5 (1.0.0) through 4.5 (1.0.9), with magicquotesgpc disabled, allows remote attackers to read arbitrary files and possibly cause a denial of service via a query string that ends with a NULL character.
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (comnfnaddressbook) 0.4 component for Mambo and Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter to (1) components/comnfnaddressbook/nfnaddressbook.php or (2) administrator/components/comnfnaddressbook/nfnaddressbook.php.
The dofreePDF function in includes/pdf.php in Mambo 4.6.1 does not properly check access rights for database content, which allows remote attackers to read certain content via unspecified vectors.
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the comcontent component (content.php).
SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the userrating parameter.
PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfigabsolutepath parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2004-1693.
PHP remote file inclusion vulnerability in about.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
PHP remote file inclusion vulnerability in administrator/components/combayesiannaivefilter/lang.php in the bayesiannaivefilter component (combayesiannaivefilter) 1.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
PHP remote file inclusion vulnerability in Function.php in Mambo 4.5 (1.0.9) allows remote attackers to execute arbitrary PHP code by modifying the mosConfigabsolutepath parameter to reference a URL on a remote web server that contains the code.
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the comremository option.
PHP remote file inclusion vulnerability in htmltemplate.php in the Chad Auld MOStlyContent Editor (MOStlyCE) as created on May 2006, a component for Mambo 4.5.4, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) comcomment.php.
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (combabackup) for Mambo 1.1 allows remote attackers to include arbitrary files via the mosConfigabsolutepath parameter.
DISPUTED PHP remote file inclusion vulnerability in contxtd.class.php in the Contacts XTD (ContXTD) component for Mambo (comcontxtd) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter. NOTE: another researcher has disputed this issue, saying that the software prevents the attack by checking whether VALIDMOS is defined.
DISPUTED PHP remote file inclusion vulnerability in contentpublisher.php in the contentpublisher component (comcontentpublisher) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter. NOTE: this issue has been disputed by third parties who state that contentpublisher.php protects against direct request in the most recent version. The original researcher is known to be frequently inaccurate.
DISPUTED PHP remote file inclusion vulnerability in anjel.index.php in ANJEL (formerly MaMML) Component (comanjel) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter. NOTE: this issue has been disputed by a third party, who says that $mosConfigabsolutepath is set in a configuration file.
DISPUTED PHP remote file inclusion vulnerability in admin.x-shop.php in the x-shop component (comx-shop) 1.7 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter. NOTE: this issue has been disputed by third party researchers, stating that there is no mosConfigabsolutepath parameter and no admin.x-shop.php file in the reported package.
PHP remote file inclusion vulnerability in archive.php in the mosListMessenger Component (comlm) before 20060719 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
PHP remote file inclusion vulnerability in catalogshop.php in the CatalogShop component for Mambo (comcatalogshop) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
Unspecified vulnerability in Prince Clan (Princeclan) Chess component (compcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (comextcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code via a URL in (1) the CONFIGEXT[LANGUAGESDIR] parameter to adminevents.php, (2) the mosConfigabsolutepath parameter to extcalendar.php, or (3) the CONFIGEXT[LIBDIR] parameter to lib/mail.inc.php.
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfigabsolutepath parameter.
PHP remote file inclusion vulnerability in comcalendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter.