Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Mambo 4.x
This vulnerability report for Mambo 4.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Mambo 4.x then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor N/A

Product Link View Here (Link to external site)

Affected By 25 Secunia advisories
35 Vulnerabilities

Monitor Product Receive alerts for this product

Unpatched 16% (4 of 25 Secunia advisories)

Most Critical Unpatched
The most severe unpatched Secunia advisory affecting Mambo 4.x, with all vendor patches applied, is rated Moderately critical .




25 Secunia Advisories in 2003-2009
Secunia has issued a total of 25 Secunia advisories in 2003-2009 for Mambo 4.x. Currently, 16% (4 out of 25) are marked as unpatched with the most severe being rated Moderately critical

More information about the specific Secunia advisories affecting Mambo 4.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Mambo Cross-Site Scripting and File Upload Vulnerabilities
Unpatched. Secunia Advisory 1 of 5 in 2008. 3,353 views.
Release Date:
2008-08-18
Secunia Advisory ID:
SA31528
Solution Status:
Unpatched
Criticality:
Impact:
Cross Site Scripting
System access
Where:
From remote
Short Description:
Some vulnerabilities have been discovered in Mambo, which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to compromise a vulnerable system. [Read More]


Mambo Two File Inclusion Vulnerabilities
Vendor Patch. Secunia Advisory 2 of 5 in 2008. 4,007 views.
Release Date:
2008-06-16
Secunia Advisory ID:
SA30685
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Exposure of sensitive information
System access
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Mambo, which can be exploited by malicious people to disclose sensitive information and compromise a vulnerable system. [Read More]


Mambo Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 3 of 5 in 2008. 4,640 views.
Release Date:
2008-05-26
Secunia Advisory ID:
SA30343
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Manipulation of data
Exposure of sensitive information
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Mambo, which can be exploited by malicious people to conduct SQL injection or HTTP response splitting attacks. [Read More]


Mambo Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 4 of 5 in 2008. 9,436 views.
Release Date:
2008-01-29
Secunia Advisory ID:
SA28670
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Manipulation of data
Exposure of system information
Where:
From remote
Short Description:
AmnPardaz Security Research Team have discovered some vulnerabilities and a weakness in Mambo, which can be exploited by malicious people to disclose system information, conduct cross-site scripting and cross-site request forgery attacks, and to manipulate data. [Read More]


Mambo Search Denial of Service
Vendor Patch. Secunia Advisory 5 of 5 in 2008. 8,444 views.
Release Date:
2008-01-11
Secunia Advisory ID:
SA28392
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been reported in Mambo, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Mambo Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 4 in 2007. 11,249 views.
Release Date:
2007-12-27
Secunia Advisory ID:
SA28251
Solution Status:
Vendor Patch
Criticality:
Impact:
Unknown
Cross Site Scripting
System access
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Mambo, one with an unknown impact and others, which can be exploited by malicious people to conduct cross-site scripting attacks or to compromise a vulnerable system. [Read More]


Mambo Two Cross-Site Scripting Vulnerabilities
Unpatched. Secunia Advisory 2 of 4 in 2007. 10,548 views.
Release Date:
2007-12-19
Secunia Advisory ID:
SA28133
Solution Status:
Unpatched
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Beenu Arora has discovered two vulnerabilities in Mambo, which can be exploited by malicious people to conduct cross-site scripting attacks. [Read More]


Mambo Unspecified Bypass Vulnerabilities
Vendor Patch. Secunia Advisory 3 of 4 in 2007. 11,639 views.
Release Date:
2007-05-03
Secunia Advisory ID:
SA25039
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Mambo, which can be exploited by malicious people to bypass certain security restrictions. [Read More]


Mambo Unspecified Content Edit Cancel SQL Injection
Vendor Patch. Secunia Advisory 4 of 4 in 2007. 13,984 views.
Release Date:
2007-02-05
Secunia Advisory ID:
SA24044
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
From remote
Short Description:
Omid has reported a vulnerability in Mambo, which can be exploited by malicious users to conduct SQL injection attacks. [Read More]


Mambo Multiple Vulnerabilities
Partial Fix. Secunia Advisory 1 of 4 in 2006. 14,976 views.
Release Date:
2006-10-05
Secunia Advisory ID:
SA22221
Solution Status:
Partial Fix
Criticality:
Impact:
Cross Site Scripting
Manipulation of data
Where:
From remote
Short Description:
Some vulnerabilities have been discovered in Mambo, which can be exploited by malicious people to conduct cross-site scripting, script insertion and SQL injection attacks. [Read More]


Mambo "id" Parameter SQL Injection Vulnerability
Vendor Patch. Secunia Advisory 2 of 4 in 2006. 15,122 views.
Release Date:
2006-08-28
Secunia Advisory ID:
SA21644
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
From remote
Short Description:
Omid has discovered a vulnerability in Mambo, which can be exploited by malicious users to conduct SQL injection attacks. [Read More]


Mambo "Submit WebLink" SQL Injection Vulnerabilities
Vendor Patch. Secunia Advisory 3 of 4 in 2006. 14,245 views.
Release Date:
2006-06-19
Secunia Advisory ID:
SA20745
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
From remote
Short Description:
Two vulnerabilities have been discovered in Mambo, which can be exploited by malicious people to conduct SQL injection attacks. [Read More]


Mambo SQL Injection and File Inclusion Vulnerabilities
Vendor Patch. Secunia Advisory 4 of 4 in 2006. 23,248 views.
Release Date:
2006-02-22
Secunia Advisory ID:
SA18935
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
System access
Where:
From remote
Short Description:
James Bercegay has reported some vulnerabilities in Mambo, which can be exploited by malicious people to conduct SQL injection attacks and potentially compromise a vulnerable system. [Read More]


Mambo "register_globals" Emulation Layer Overwrite Vulnerability
Vendor Patch. Secunia Advisory 1 of 4 in 2005. 18,283 views.
Release Date:
2005-11-17
Secunia Advisory ID:
SA17622
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
System access
Where:
From remote
Short Description:
peter MC tachatte has discovered a vulnerability in Mambo, which can be exploited by malicious people to manipulate certain information and compromise a vulnerable system. [Read More]


Mambo Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 2 of 4 in 2005. 14,857 views.
Release Date:
2005-06-15
Secunia Advisory ID:
SA15710
Solution Status:
Vendor Patch
Criticality:
Impact:
Unknown
Spoofing
Manipulation of data
Where:
From remote
Short Description:
Some vulnerabilities have been reported in Mambo, where some have unknown impacts and others can be exploited by malicious people to conduct spoofing and SQL injection attacks. [Read More]


Mambo "GLOBALS['mosConfig_absolute_path']" File Inclusion
Vendor Patch. Secunia Advisory 3 of 4 in 2005. 48,540 views.
Release Date:
2005-02-21
Secunia Advisory ID:
SA14337
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability has been reported in Mambo, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Mambo Global Variables Security Bypass Vulnerability
Vendor Patch. Secunia Advisory 4 of 4 in 2005. 11,779 views.
Release Date:
2005-02-03
Secunia Advisory ID:
SA14124
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
A vulnerability has been reported in Mambo, which can be exploited by malicious people to bypass certain security restrictions. [Read More]


Mambo Cross Site Scripting and SQL Injection Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 3 in 2004. 11,297 views.
Release Date:
2004-03-17
Secunia Advisory ID:
SA11140
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Exposure of sensitive information
Manipulation of data
Cross Site Scripting
Where:
From remote
Short Description:
JeiAr has discovered some vulnerabilities in Mambo, allowing malicious people to conduct SQL injection and Cross Site Scripting attacks. [Read More]


Mambo "Itemid" Parameter Cross-Site Scripting Vulnerability
Unpatched. Secunia Advisory 2 of 3 in 2004. 9,911 views.
Release Date:
2004-02-06
Secunia Advisory ID:
SA10804
Solution Status:
Unpatched
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
David Sopas Ferreira has reported a vulnerability Mambo, allowing malicious people to conduct cross-site scripting attacks. [Read More]


Mambo Arbitrary File Inclusion Vulnerability
Vendor Workaround. Secunia Advisory 3 of 3 in 2004. 10,528 views.
Release Date:
2004-01-20
Secunia Advisory ID:
SA10677
Solution Status:
Vendor Workaround
Criticality:
Impact:
System access
Where:
From remote
Short Description:
FraMe has reported a vulnerability in Mambo server, allowing malicious people to execute arbitrary code on a vulnerable system. [Read More]


Mambo Server SQL Injection Vulnerabilities
Vendor Patch. Secunia Advisory 1 of 4 in 2003. 11,160 views.
Release Date:
2003-12-11
Secunia Advisory ID:
SA10413
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
From remote
Short Description:
Two vulnerabilities have been reported in Mambo Server, which can be exploited by malicious people to manipulate SQL queries. [Read More]


Mambo SQL Injection Vulnerabilities
Vendor Patch. Secunia Advisory 2 of 4 in 2003. 11,265 views.
Release Date:
2003-09-19
Secunia Advisory ID:
SA9796
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Exposure of system information
Exposure of sensitive information
Where:
From remote
Short Description:
Multiple vulnerabilities have been identified in Mambo allowing malicious users to manipulate SQL queries and send SPAM anonymously. [Read More]


Mambo SiteServer Unauthorised Administrative Access
Vendor Patch. Secunia Advisory 3 of 4 in 2003. 8,246 views.
Release Date:
2003-02-27
Secunia Advisory ID:
SA8168
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
From remote
Short Description:
A vulnerability in Mambo SiteServer can be exploited by malicious users to gain access to the administrative interface. [Read More]


Mambo SiteServer arbitrary code execution
Vendor Patch. Secunia Advisory 4 of 4 in 2003. 6,944 views.
Release Date:
2003-01-13
Secunia Advisory ID:
SA7853
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mambo SiteServer allows users to place arbitrary php code on the server. Also Mambo suffers Cross Site Scripting in multiple scripts. [Read More]


Mambo SiteServer multiple vulnerabilities
Unpatched. Secunia Advisory 1 of 1 in 2002. 6,567 views.
Release Date:
2002-12-13
Secunia Advisory ID:
SA7708
Solution Status:
Unpatched
Criticality:
Impact:
Cross Site Scripting
Exposure of system information
Privilege escalation
Where:
From remote
Short Description:
Mambo SiteServer suffers multiple vulnerabilities. [Read More]