Back to search
CVE-2005-4320
Published: Dec 17, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
Limbo CMS 1.0.4.2 and earlier allows remote attackers to obtain the installation path of the application via a direct request to (1) doc.inc.php, (2) element.inc.php, and (3) node.inc.php, which leaks the path in an error message.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
18063
third-party-advisory
x_refsource_SECUNIA
21757
vdb-entry
x_refsource_OSVDB
1015364
vdb-entry
x_refsource_SECTRACK
21758
vdb-entry
x_refsource_OSVDB
http://rgod.altervista.org/limbo1042_xpl.html
x_refsource_MISC
21759
vdb-entry
x_refsource_OSVDB
20051214 LIMBO CMS <= v1.0.4.2 _SERVER[] array overwrite / remote code execution
mailing-list
x_refsource_BUGTRAQ
ADV-2005-2932
vdb-entry
x_refsource_VUPEN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now