CVE-2006-7149
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script
Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the query string to (a) index.php, which reflects the string in an error message from mod_login.php.
and the (2) mcname parameter to (b) moscomment.php and (c) com_comment.php.
MEDIUM · CVSS 4.3
EPSS 0.00547
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0