7.5

CVE-2008-2686

Exploit
webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Flux CmsFlux Cms Version <= 1.50
Flux CmsFlux Cms Version1.2
Flux CmsFlux Cms Version1.3
Flux CmsFlux Cms Version1.4
Flux CmsFlux Cms Version1.31
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.94% 0.891
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/bid/29618
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/42961
https://www.exploit-db.com/exploits/5767