CVE-2008-3203
AuraCMS 2.2-2.2.2 - RCE
Title source: llmDescription
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
Exploits (1)
References (5)
Scores
EPSS
0.0483
EPSS Percentile
89.4%
Classification
CWE
CWE-287
Status
draft
Affected Products (3)
auracms/auracms
auracms/auracms
auracms/auracms
Timeline
Published
Jul 17, 2008
Tracked Since
Feb 18, 2026