Back

CVE-2006-0871

Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.

Published: Feb 24, 2006 Modified: Jun 16, 2026
CWE-22

CVSS Metrics

Affected Products (2)

Vendor Product Version
mambo mambo 4.5.3h
mambo mambo 4.5.3h

GitHub Security Advisory GHSA-wmxw-xmgw-6xh3

Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and...

Risk Scores

CVSS Score 6.4 / 10
EPSS Score 1.71%

Top 24% most likely to be exploited

Threat Score 26.1 / 100

Data Sources

NVD EPSS GitHub