CVE
- Id
- 32803
- CVE No.
- CVE-2008-2686
- Status
- Candidate
- Description
- webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename.
- Phase
- Assigned (20080613)
- Votes
- None (candidate not yet proposed)
- Comments