EIP-2026-109308
PRE-CVEMambo Site Server 4.0.14 - 'contact.php' Unauthorized Mail Relay
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-109308. PoCs published by Lifo Fifo.
AI-analyzed exploit summary The provided text describes SQL injection and email spam vulnerabilities in Mambo Open Source Server 4.0.14, specifically in the banners.php, emailfriend/emailarticle.php, and contact.php modules. It includes a sample URL demonstrating the email spam vulnerability.
Description
Mambo Site Server 4.0.14 - 'contact.php' Unauthorized Mail Relay
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Lifo Fifo · textwebappsphp
https://www.exploit-db.com/exploits/23160
The provided text describes SQL injection and email spam vulnerabilities in Mambo Open Source Server 4.0.14, specifically in the banners.php, emailfriend/emailarticle.php, and contact.php modules. It includes a sample URL demonstrating the email spam vulnerability.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target:
Mambo Open Source Server 4.0.14
No auth needed
Prerequisites:
Access to vulnerable Mambo Open Source Server instance
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026