CVE-2008-5226

MambAds 1.0 RC1 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view action to index.php, a different vector than CVE-2007-5177.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Houssamix · perlwebappsphp
https://www.exploit-db.com/exploits/5692

Scores

EPSS 0.0048
EPSS Percentile 65.1%

Details

CWE
CWE-89
Status published
Products (2)
mambads/mambads 1.0 rc1 (2 CPE variants)
mambo/mambo
Published Nov 25, 2008
Tracked Since Feb 18, 2026