Mambo Foundation · Mambo · CVE-2008-6481
**Name of the Vulnerable Software and Affected Versions**
Joomla! version 1.0.2
Mambo version 1.0.2
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the `id` parameter in an edit task to "index.php".
**Recommendations**
For Joomla! version 1.0.2, avoid using the `id` parameter in the affected API endpoint until the issue is resolved.
For Mambo version 1.0.2, restrict access to the vulnerable component to minimize the risk of exploitation.