CVE-2006-2142
Limbo CMS <= 1.04 - Remote File Inclusion via classes_dir Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2142. PoCs published by [Oo].
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Limbo CMS <= 1.04. The vulnerability allows an attacker to include arbitrary remote files via the 'classes_dir' parameter in the 'sql.php' script, potentially leading to remote code execution.
Description
PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Limbo CMS <= 1.04. The vulnerability allows an attacker to include arbitrary remote files via the 'classes_dir' parameter in the 'sql.php' script, potentially leading to remote code execution.