CVE-2006-6800
Limbo CMS Event Module 1.0 - Remote File Inclusion via lm_absolute_path Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6800. PoCs published by Mehmet Ince.
AI-analyzed exploit summary This exploit demonstrates a Remote File Include (RFI) vulnerability in Limbo CMS's event module. The vulnerability arises from improper input validation in the 'lm_absolute_path' parameter, allowing an attacker to include remote PHP files.
Description
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter.
Exploits (1)
This exploit demonstrates a Remote File Include (RFI) vulnerability in Limbo CMS's event module. The vulnerability arises from improper input validation in the 'lm_absolute_path' parameter, allowing an attacker to include remote PHP files.