Back

CVE-2005-4318

SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals off, allows remote attackers to execute arbitrary SQL commands via the _SERVER[REMOTE_ADDR] parameter, which modifies the underlying $_SERVER variable.

Published: Dec 17, 2005 Modified: Jun 16, 2026

CVSS Metrics

GitHub Security Advisory GHSA-g3rq-5w5q-9rf3

SQL injection vulnerability in index.php in Limbo CMS 1.0.4.2 and earlier, with register_globals...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.65%

Top 25% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub