SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/26366 | vdb entry |
http://secunia.com/advisories/19891 | third party advisory patch vendor advisory |
https://www.exploit-db.com/exploits/1751 | exploit |
http://www.securityfocus.com/archive/1/433221/100/0/threaded | mailing list |
http://securityreason.com/securityalert/893 | third party advisory |
http://forum.limboforge.org/index.php?topic=6.0 | patch |