Unrated severityNVD Advisory· Published Jun 13, 2008· Updated Apr 23, 2026
CVE-2008-2686
CVE-2008-2686
Description
webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename.
Affected products
5cpe:2.3:a:flux_cms:flux_cms:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:flux_cms:flux_cms:*:*:*:*:*:*:*:*range: <=1.50
- cpe:2.3:a:flux_cms:flux_cms:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:flux_cms:flux_cms:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:flux_cms:flux_cms:1.31:*:*:*:*:*:*:*
- cpe:2.3:a:flux_cms:flux_cms:1.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.