vendor:
Limbo CMS
by:
Coloss / Epsilon and /str0ke
9,3
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Limbo CMS
Affected Version From: 1.0.4.2
Affected Version To: 1.0.4.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Limbo CMS <= 1.0.4.2 (ItemID) Remote Code Execution Exploit
Limbo CMS version 1.0.4.2 and prior are vulnerable to a remote code execution vulnerability. The vulnerability is due to the application not properly sanitizing user-supplied input passed via the 'ItemID' parameter to the 'index.php' script. This can be exploited to execute arbitrary commands on the affected system with the privileges of the webserver process.
Mitigation:
Upgrade to the latest version of Limbo CMS