Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15062
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-2064
http://www.systemsecure.org/advisories/ssadvisory06022004.php