Known Vulnerabilities for products from Limbo Cms
Listed below are 14 of the newest known vulnerabilities associated with the vendor "Limbo Cms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2008-6078 json | SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote attacker... | Not Provided | 2009-02-06 | 2026-04-23 |
| CVE-2008-0734 json | SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attackers to... | Not Provided | 2008-02-13 | 2026-04-23 |
| CVE-2007-6564 json | Cross-site scripting (XSS) vulnerability in admin.php in Limbo CMS 1.0.4.2 allows remote attackers to inject arbitrary web sc... | Not Provided | 2007-12-28 | 2026-04-23 |
| CVE-2006-6800 json | PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execu... | Not Provided | 2006-12-28 | 2026-04-23 |
| CVE-2006-4860 json | Multiple unspecified vulnerabilities in (1) index.php, (2) minixml.inc.php, (3) doc.inc.php, (4) element.inc.php, (5) node.in... | 10 - HIGH | 2006-09-19 | 2008-09-05 |
| CVE-2006-4859 json | Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mambo) C... | 7.5 - HIGH | 2006-09-19 | 2017-10-19 |
| CVE-2006-2363 json | SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitr... | 5.1 - MEDIUM | 2006-05-15 | 2018-10-18 |
| CVE-2006-2142 json | PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to ex... | Not Provided | 2006-05-02 | 2025-04-03 |
| CVE-2006-1662 json | The frontpage option in Limbo CMS 1.0.4.2 and 1.0.4.1 allows remote attackers to execute arbitrary PHP commands via the Itemi... | Not Provided | 2006-04-07 | 2025-04-03 |
| CVE-2006-0934 json | Cross-site scripting (XSS) vulnerability in webinsta Limbo 1.0.4.2 allows remote attackers to inject arbitrary web script or ... | Not Provided | 2006-02-28 | 2025-04-03 |
| CVE-2005-4320 json | Limbo CMS 1.0.4.2 and earlier allows remote attackers to obtain the installation path of the application via a direct request... | Not Provided | 2005-12-17 | 2025-04-03 |
| CVE-2005-4319 json | Directory traversal vulnerability in index2.php in Limbo CMS 1.0.4.2 and earlier allows remote attackers to include arbitrary... | Not Provided | 2005-12-17 | 2025-04-03 |
| CVE-2005-4318 json | SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers... | Not Provided | 2005-12-17 | 2025-04-03 |
| CVE-2005-4317 json | Limbo CMS 1.0.4.2 and earlier, with register_globals off, does not protect the $_SERVER variable from external modification, ... | Not Provided | 2005-12-17 | 2025-04-03 |