PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to execute arbitrary PHP code via a URL in the lm_absolute_path parameter.
References
Configurations
Information
Published : 2006-12-28 13:28
Updated : 2018-10-17 14:49
NVD link : CVE-2006-6800
Mitre link : CVE-2006-6800
JSON object : View
CWE
Products Affected
limbo_cms
- event_module