Back

CVE-2004-1826

SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

Published: Mar 16, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
mambo mambo_open_source_4.5 1.0.0
mambo mambo_open_source_4.5 1.0.1
mambo mambo_open_source_4.5 1.0.2
mambo mambo_open_source_4.5 1.0.3
mambo mambo_open_source_4.5 1.0.3beta

GitHub Security Advisory GHSA-f2fp-44fh-jxwr

SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.23%

Top 34% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub