CVE-2008-2686
Flux Cms < 1.50 - Improper Input Validation
Title source: ruleDescription
webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename.
Exploits (1)
Scores
EPSS
0.0470
EPSS Percentile
89.4%
Details
CWE
CWE-20
Status
published
Products (5)
flux_cms/flux_cms
1.2
flux_cms/flux_cms
1.3
flux_cms/flux_cms
1.4
flux_cms/flux_cms
1.31
flux_cms/flux_cms
< 1.50
Published
Jun 13, 2008
Tracked Since
Feb 18, 2026