SQL injection vulnerability in the weblinks option (weblinks.html.php) in Limbo CMS allows remote attackers to execute arbitrary SQL commands via the catid parameter.
https://www.exploit-db.com/exploits/1751
https://exchange.xforce.ibmcloud.com/vulnerabilities/26366
http://www.securityfocus.com/archive/1/433221/100/0/threaded
http://securityreason.com/securityalert/893