Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: CGI abuses --> Category: attack

Limbo catid Parameter SQL Injection Vulnerability Vulnerability Scan


Vulnerability Scan Summary
Tries to affect DB queries in Limbo CMS

Detailed Explanation for this Vulnerability Test

Synopsis :

The remote web server contains a PHP script that is affected by a SQL
injection issue.

Description :

The remote host is running Limbo CMS, a content-management system
written in PHP.

The version of Limbo CMS installed on the remote host fails to
sanitize input to the 'catid' parameter of the 'index.php' script
before using it in a database query. An unauthenticated attacker may
be able to leverage this issue to manipulate SQL queries to uncover
password hashes for arbitrary users of the affected application.

Note that successful exploitation requires that Limbo is configured to
use MySQL for its database backend, which is not the default.

See also :

http://www.securityfocus.com/archive/1/433221/30/0/threaded
http://forum.limboforge.org/index.php?topic=6.0
http://limboforge.org/web/component/option,com_remository/Itemid,1/func,fileinfo/id,115/

Solution :

Apply Cumulative Patch v8 to Limbo 1.0.4.2 as referenced in the
advisories above.

Threat Level:

Medium / CVSS Base Score : 4
(AV:R/AC:H/Au:NR/C:P/A:N/I:P/B:N)

Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.