CVE-2006-1794

Mambo < 4.5.3h - SQL Injection via mosGetParam and mosMenuCheck Functions

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1794.

AI-analyzed exploit summary This is a detailed technical analysis of multiple vulnerabilities in Mambo CMS, including SQL injection, authentication bypass, and local file inclusion. It provides code snippets, exploitation techniques, and mitigation advice.

Description

SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/43835

This is a detailed technical analysis of multiple vulnerabilities in Mambo CMS, including SQL injection, authentication bypass, and local file inclusion. It provides code snippets, exploitation techniques, and mitigation advice.

Classification
Writeup 100%
Attack Type
Sqli | Auth Bypass | Other
Complexity
Trivial
Reliability
Reliable
Target: Mambo CMS <= 4.5.3h
No auth needed
Prerequisites: Target running Mambo CMS <= 4.5.3h · Magic quotes disabled in PHP
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (9)

Core 9
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18935
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23402
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0719
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2006-02/0463.html
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16775
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24951
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23503

Scores

EPSS 0.0553
EPSS Percentile 91.8%

Details

Status published
Products (13)
mambo/mambo 4.0.14
mambo/mambo 4.5.1_1.0.9
mambo/mambo 4.5.1a (3 CPE variants)
mambo/mambo 4.5.2
mambo/mambo 4.5.2.1
mambo/mambo 4.5.2.2
mambo/mambo 4.5.2.3
mambo/mambo 4.5.3h
mambo/mambo 4.5_1.0.0
mambo/mambo 4.5_1.0.1
... and 3 more
Published Apr 17, 2006
Tracked Since Feb 18, 2026