7.5
CVSSv2

CVE-2008-6078

Published: 06/02/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote malicious users to execute arbitrary SQL commands via the id parameter in a pms action to index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

limbo_cms com_privmsg

Exploits

/* Limbo CMS (Private Messaging Component) Remote SQL Injection Vulnerability -------------------------------------------------------------------------- StAkeR[at]hotmail[dot]it wwwlimboportalcom/indexphp/option/downloads/task/download/id/108 -------------------------------------------------------------------------- ...