6
CVSSv2

CVE-2010-4313

Published: 02/12/2010 Updated: 10/10/2018
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users to execute arbitrary code by uploading a .php file, and then accessing it via a direct request to the file in uploads/.

Vulnerable Product Search on Vulmon Subscribe to Product

novo-ws orbis cms 1.0.2

Exploits

'Orbis CMS' Arbitrary Script Execution Vulnerability (CVE-2010-4313) Mark Stanislav - markstanislav@gmailcom I DESCRIPTION --------------------------------------- A vulnerability exists in the 'Orbis CMS' fileman_file_uploadphp script that allows any authenticated user to upload a PHP script and then run it without restriction II TESTED ...
Orbis CMS version 102 suffers from a remote shell upload vulnerability ...