Lucene search

K

Estateagent Security Vulnerabilities

cve
cve

CVE-2006-4322

PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

7.9AI Score

0.051EPSS

2006-08-24 01:04 AM
21
cve
cve

CVE-2008-0517

SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.

8.4AI Score

0.001EPSS

2008-01-31 08:00 PM
18