7.5
CVSSv2

CVE-2008-2686

Published: 13/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and previous versions allows remote malicious users to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename.

Vulnerable Product Search on Vulmon Subscribe to Product

flux cms flux cms 1.3

flux cms flux cms 1.31

flux cms flux cms 1.4

flux cms flux cms

flux cms flux cms 1.2

Exploits

<?php /* ------------------------------------------------------------------------ Flux CMS <= 150 (loadsavephp) Remote Arbitrary File Overwrite Exploit ------------------------------------------------------------------------ author: EgiX mail: n0b0d13s[at]gmail[dot]com link: wwwflux-cmsorg/ [-] vulnerable ...