SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mambo | Mambo | 4.5.0.2 (including) | 4.5.0.2 (including) |
| Mambo | Mambo | 4.5.1.3 (including) | 4.5.1.3 (including) |
| Mambo | Mambo | 4.5.1a-a (including) | 4.5.1a-a (including) |
| Mambo | Mambo | 4.5.2 (including) | 4.5.2 (including) |
| Mambo | Mambo | 4.5.2.2 (including) | 4.5.2.2 (including) |
| Mambo | Mambo | 4.5_1.0.9 (including) | 4.5_1.0.9 (including) |