CVE-2014-9574: Fluxbb

High severity, CVSS 9.3. EPSS: 2.6% chance of exploitation in the next 30 days.

Directory traversal vulnerability in install.php in FluxBB before 1.5.8 allows remote attackers to include and execute arbitrary local install.php files via a .. (dot dot) in the install_lang parameter.

Affected products

  • Fluxbb Fluxbb: up to and including 1.5.7

Published 2015-02-03. Last modified 2026-06-17.