CVE-2004-1826
Mambo Open Source 4.5 - SQL Injection via Index.php ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1826. PoCs published by JeiAr.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in Mambo's 'index.php' script, where user-supplied URI input is not properly validated. An attacker can exploit this to manipulate database queries and potentially disclose sensitive information such as the administrator password hash.
Description
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
The provided text describes an SQL injection vulnerability in Mambo's 'index.php' script, where user-supplied URI input is not properly validated. An attacker can exploit this to manipulate database queries and potentially disclose sensitive information such as the administrator password hash.