CVE-2006-4860 describes multiple unspecified vulnerabilities across several PHP files within Limbo (aka Lite Mambo) CMS version 1.0.4.2 prior to the 20060311 release. These vulnerabilities have an unknown impact and attack vectors, affecting core components of the CMS. The vulnerability is rated with a CVSS score of 10.0, indicating critical severity with network-based attack vectors, low attack complexity, and complete compromise of confidentiality, integrity, and availability. Despite the high CVSS score, the Exploit Prediction Scoring System (EPSS) is low at 0.03113, suggesting a low probability of exploitation. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.4.1CPE matchmatch criteria | cpe:2.3:a:limbo_cms:limbo_cms:1.0.4.1:*:*:*:*:*:*:* | ||
1.0.4.2CPE matchmatch criteria | cpe:2.3:a:limbo_cms:limbo_cms:1.0.4.2:*:*:*:*:*:*:* | ||
1.0.4.2lCPE matchmatch criteria | cpe:2.3:a:limbo_cms:limbo_cms:1.0.4.2l:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.