CVE-2005-4318

Limbo CMS <1.0.4.2 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers to execute arbitrary SQL commands via the _SERVER[REMOTE_ADDR] parameter, which modifies the underlying $_SERVER variable.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1373

Scores

EPSS 0.0162
EPSS Percentile 81.9%

Details

Status published
Published Dec 17, 2005
Tracked Since Feb 18, 2026