Vulnerability Details CVE-2008-3203
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web content via a modified id parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.024
EPSS Ranking 84.4%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2008-3203
-
cpe:2.3:a:auracms:auracms:2.2
-
cpe:2.3:a:auracms:auracms:2.2.1
-
cpe:2.3:a:auracms:auracms:2.2.2