Back to search
CVE-2005-4318
Published: Dec 17, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers to execute arbitrary SQL commands via the _SERVER[REMOTE_ADDR] parameter, which modifies the underlying $_SERVER variable.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
18063
third-party-advisory
x_refsource_SECUNIA
21753
vdb-entry
x_refsource_OSVDB
1015364
vdb-entry
x_refsource_SECTRACK
http://rgod.altervista.org/limbo1042_xpl.html
x_refsource_MISC
255
third-party-advisory
x_refsource_SREASON
15871
vdb-entry
x_refsource_BID
20051214 LIMBO CMS <= v1.0.4.2 _SERVER[] array overwrite / remote code execution
mailing-list
x_refsource_BUGTRAQ
ADV-2005-2932
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now