PT-2006-4156 · Mambo · Mambo

Rgod

·

Published

2006-06-27

·

Updated

2018-10-18

·

CVE-2006-3262

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mambo versions 4.6rc1 and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands via the title parameter in the Weblinks module. This is a SQL injection vulnerability, which can lead to unauthorized access and manipulation of database content.
Recommendations For Mambo versions 4.6rc1 and earlier, avoid using the title parameter in the Weblinks module until a fix is available. As a temporary workaround, consider restricting access to the Weblinks module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3262

Affected Products

Mambo