Multiple SQL injection vulnerabilities in Mambo 4.6.x allow remote attackers to execute arbitrary SQL commands via the mcname parameter to (1) moscomment.php and (2) com_comment.php.
| Software | From | Fixed in |
|---|---|---|
| mambo / mambo_open_source | 4.6 | 4.6.x |
| mambo / mambo_open_source | 4.6.1 | 4.6.1.x |
| mambo / mambo_open_source | 4.6-rc1 | 4.6-rc1.x |
| mambo / mambo_open_source | 4.6-rc2 | 4.6-rc2.x |