Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Com Privmsg HIGH 7.5
CVE-2008-6078

SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote attackers to execute arbitrary S…

No fix yet
Fix from $1,950 2009-02-06
Limbo Cms HIGH 7.5
CVE-2008-0734

SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL c…

Fix: after 1.0.4.2
Fix from $1,950 2008-02-13
Event Module MEDIUM 6.8
CVE-2006-6800

PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code vi…

No fix yet
Fix from $1,600 2006-12-28
Limbo Cms HIGH 10.0
CVE-2006-4860

Multiple unspecified vulnerabilities in (1) index.php, (2) minixml.inc.php, (3) doc.inc.php, (4) element.inc.php, (5) node.inc.php, (6) treecomp.inc.…

Patch available
Fix from $1,950 2006-09-19
Limbo Cms HIGH 7.5
CVE-2006-4859EPSS 7%

Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mambo) CMS 1.0.4.2L and earlier …

No fix yet
Fix from $1,950 2006-09-19
Limbo Cms MEDIUM 5.1
CVE-2006-2363

SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the…

Patch available
Fix from $1,600 2006-05-15
Limbo Cms MEDIUM 6.4
CVE-2006-2142EPSS 8%

PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code…

No fix yet
Fix from $1,600 2006-05-02
Limbo Cms HIGH 7.5
CVE-2006-1662

The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the Itemid parameter in index.php.

No fix yet
Fix from $1,950 2006-04-07
Limbo Cms MEDIUM 6.8
CVE-2005-4317EPSS 5%

Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, which allows remote atta…

Fix: after 1.0.4.2
Fix from $1,600 2005-12-17
Limbo Cms MEDIUM 5.0
CVE-2005-4319

Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbitrary PHP files via ".." sequ…

Fix: after 1.0.4.2
Fix from $1,600 2005-12-17
Limbo Cms MEDIUM 5.0
CVE-2005-4320

Limbo CMS 1.0.4.2 and earlier allows remote attackers to obtain the installation path of the application via a direct request to (1) doc.inc.php, (2)…

Fix: after 1.0.4.2
Fix from $1,600 2005-12-17