Mamboxchange maintains a modest portfolio of web-based applications and extensions including Laithai, a helpdesk system, and various Mambo-ecosystem components, attracting vulnerability disclosures that center on server-side injection attack surfaces. The recurring weakness classes—code injection and SQL injection—reflect the injection-prone parsing and database-query construction typical of server-side web frameworks, and vulnerabilities in this vendor have a strong tendency to acquire public exploit code. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mamboxchange over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4203HIGH PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in | Aug 17, 2006 | 7.5 | 35 | NO | YES |
CVE-2007-1992HIGH Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote attackers to execute arbitrary PHP code via a URL in the mos | Apr 12, 2007 | 7.5 | 32 | NO | YES |
CVE-2006-4858MEDIUM PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitr | Sep 19, 2006 | 6.8 | 29 | NO | YES |
CVE-2006-4282HIGH PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows remote attackers to execute arbi | Aug 22, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-4241HIGH PHP remote file inclusion vulnerability in processor/reporter.sql.php in the Reporter Mambo component (com_reporter) allows remote attackers to execute arbitrary PHP code via a URL | Aug 21, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-3930HIGH PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to execute arbitrary PHP code via | Jul 31, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-6051HIGH PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and Joomla! allows remote attackers to execute arbitrary PHP cod | Nov 22, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-5254HIGH PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), aka regdetailed, 4.1 and earlier | Oct 12, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-4195MEDIUM PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals an | Aug 17, 2006 | 6.8 | 28 | NO | YES |
CVE-2006-3748MEDIUM PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attacker | Jul 21, 2006 | 6.8 | 28 | NO | YES |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mamboxchange.
Media articles that mention a CVE ID that affects a product developed by Mamboxchange — matched by CVE ID, not by vendor name.