7.5
CVSSv2

CVE-2006-4859

Published: 19/09/2006 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mambo) CMS 1.0.4.2L and previous versions allows remote malicious users to upload PHP code to the images/contact folder via a filename with a double extension in the contact_attach parameter in a contact option in index.php, which bypasses an insufficiently restrictive regular expression.

Vulnerable Product Search on Vulmon Subscribe to Product

limbo cms limbo cms 1.0.4.1

limbo cms limbo cms 1.0.4.2

limbo cms limbo cms 1.0.4.2l

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? print_r(' ----------------------------------------------------------------------------- Limbo <= 1042L "com_contact" remote commands execution exploit by rgod rgod@autisticiorg site: retrogodaltervistaorg dorks: inurl:contact inurl:Itemid inurl:option attachment "Enter your name:" ...