Back

CVE-2005-2002

SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.

Published: Jun 15, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
mambo mambo 4.5.0.2
mambo mambo 4.5.1.3
mambo mambo 4.5.1a
mambo mambo 4.5.2
mambo mambo 4.5.2.2
mambo mambo 4.5_1.0.9

GitHub Security Advisory GHSA-3fvg-g788-h5q8

SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.32%

Top 31% most likely to be exploited

Threat Score 30.4 / 100

Data Sources

NVD EPSS GitHub