HIGH
webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename
Published Jun 13, 2008
7.5
HIGHCVSS 2.0
EPSS 3.94%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.