Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) com_comment.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mambo_open_source | Mambo | 4.6 (including) | 4.6 (including) |
Mambo_open_source | Mambo | 4.6-rc1 (including) | 4.6-rc1 (including) |
Mambo_open_source | Mambo | 4.6-rc2 (including) | 4.6-rc2 (including) |
Mambo_open_source | Mambo | 4.6.1 (including) | 4.6.1 (including) |