CVE-2008-3203

AuraCMS 2.2-2.2.2 - RCE

Title source: llm

Description

js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by k1tk4t · perlwebappsphp
https://www.exploit-db.com/exploits/6033

Scores

EPSS 0.0483
EPSS Percentile 89.4%

Classification

CWE
CWE-287
Status draft

Affected Products (3)

auracms/auracms
auracms/auracms
auracms/auracms

Timeline

Published Jul 17, 2008
Tracked Since Feb 18, 2026