Description
SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execute arbitrary SQL commands via the zorder parameter.
Affected products
- mambo-foundation / mambo4.6.5
- mambo-foundation / mambo4.6 – 4.6
- mambo-foundation / mambo4.6 – 4.6
- mambo-foundation / mambo4.6 – 4.6
- mambo-foundation / mambo4.6.1 – 4.6.1
- mambo-foundation / mambo4.6.2 – 4.6.2
- mambo-foundation / mambo4.6.2 – 4.6.2
- mambo-foundation / mambo4.6.2 – 4.6.2
- mambo-foundation / mambo4.6.3 – 4.6.3
- mambo-foundation / mambo4.6.4 – 4.6.4