CVE-2008-3203
AuraCMS 2.2-2.2.2 - Unauthenticated Arbitrary Content Modification via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3203. PoCs published by k1tk4t.
AI-analyzed exploit summary This Perl script exploits an arbitrary edit/add/delete vulnerability in AuraCMS <= 2.2.2 via the pages_data.php file, which lacks proper access control. It allows unauthenticated manipulation of database entries for pages.
Description
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
Exploits (1)
This Perl script exploits an arbitrary edit/add/delete vulnerability in AuraCMS <= 2.2.2 via the pages_data.php file, which lacks proper access control. It allows unauthenticated manipulation of database entries for pages.