CVE-2007-3290

LiveCMS <3.4 - Info Disclosure

Title source: llm

Description

categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message.

Exploits (1)

exploitdb WORKING POC VERIFIED
by g00ns · perlwebappsphp
https://www.exploit-db.com/exploits/4082

Scores

EPSS 0.0612
EPSS Percentile 90.8%

Details

Status published
Products (6)
livecms/livecms 3.0
livecms/livecms 3.3
livecms/livecms 3.3_rc1
livecms/livecms 3.3_rc2
livecms/livecms 3.4
livecms/livecms 3.4a
Published Jun 20, 2007
Tracked Since Feb 18, 2026