Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.57065
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: mambo
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: mambo

CVE-2006-3262
SQL injection vulnerability in the Weblinks module (weblinks.php) in
Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary
SQL commands via the title parameter.

CVE-2006-3263
SQL injection vulnerability in the Weblinks module (weblinks.php) in
Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary
SQL commands via the catid parameter.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
7.6

CVSS Vector:
AV:N/AC:H/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2006-0871
Bugtraq: 20060224 Mambo Multiple Vulnerabilities (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html
http://www.gulftech.org/?node=research&article_id=00104-02242006
http://www.osvdb.org/23505
http://secunia.com/advisories/18935
http://securityreason.com/securityalert/493
http://www.vupen.com/english/advisories/2006/0719
Common Vulnerability Exposure (CVE) ID: CVE-2006-1794
BugTraq ID: 16775
http://www.securityfocus.com/bid/16775
http://www.osvdb.org/23402
http://www.osvdb.org/23503
XForce ISS Database: mambo-index2-sql-injection(24951)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24951
Common Vulnerability Exposure (CVE) ID: CVE-2006-3262
BugTraq ID: 18492
http://www.securityfocus.com/bid/18492
Bugtraq: 20060617 Mambo <= 4.6rc1 sql injection (Google Search)
http://www.securityfocus.com/archive/1/437496/100/100/threaded
http://retrogod.altervista.org/mambo_46rc1_sql.html
http://www.osvdb.org/26624
http://securitytracker.com/id?1016334
http://secunia.com/advisories/20745
http://securityreason.com/securityalert/1158
http://www.vupen.com/english/advisories/2006/2416
Common Vulnerability Exposure (CVE) ID: CVE-2006-3263
CopyrightCopyright (C) 2008 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.