SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-3260
http://www.mamboserver.com/?option=com_content&task=view&id=207