CVE-2006-0871

Mambo 4.5.3, 4.5.3h - Path Traversal via mos_change_template Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-0871. PoCs published by GulfTech Security.

AI-analyzed exploit summary This is a detailed technical analysis of multiple vulnerabilities in Mambo CMS, including SQL injection, authentication bypass, and local file inclusion. It provides code snippets, exploitation techniques, and mitigation advice.

Description

Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.

Exploits (1)

exploitdb WRITEUP
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/43835

This is a detailed technical analysis of multiple vulnerabilities in Mambo CMS, including SQL injection, authentication bypass, and local file inclusion. It provides code snippets, exploitation techniques, and mitigation advice.

Classification
Writeup 100%
Attack Type
Sqli | Auth Bypass | Other
Complexity
Trivial
Reliability
Reliable
Target: Mambo CMS <= 4.5.3h
No auth needed
Prerequisites: Target running Mambo CMS <= 4.5.3h · Magic quotes disabled in PHP environment
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18935
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0719
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/493
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23505

Scores

EPSS 0.0167
EPSS Percentile 73.7%

Details

CWE
CWE-22
Status published
Products (1)
mambo/mambo 4.5.3h (2 CPE variants)
Published Feb 24, 2006
Tracked Since Feb 18, 2026