CVE-2005-4318

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/12/2005
Last modified:
03/04/2025

Description

SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers to execute arbitrary SQL commands via the _SERVER[REMOTE_ADDR] parameter, which modifies the underlying $_SERVER variable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:limbo_cms:limbo_cms:*:*:*:*:*:*:*:* 1.0.4.2 (including)