Vulnerabilities > CVE-2010-4313 - Unspecified vulnerability in Novo-Ws Orbis CMS 1.0.2

047910
CVSS 6.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
novo-ws
exploit available

Summary

Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users to execute arbitrary code by uploading a .php file, and then accessing it via a direct request to the file in uploads/. Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'

Vulnerable Configurations

Part Description Count
Application
Novo-Ws
1

Exploit-Db

descriptionOrbis CMS 1.0.2 - Arbitrary File Upload Vulnerability. CVE-2010-4313. Webapps exploit for php platform
fileexploits/php/webapps/15636.txt
idEDB-ID:15636
last seen2016-02-01
modified2010-11-30
platformphp
port
published2010-11-30
reporterMark Stanislav
sourcehttps://www.exploit-db.com/download/15636/
titleOrbis CMS 1.0.2 - Arbitrary File Upload Vulnerability
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/96250/orbiscms-shell.txt
idPACKETSTORM:96250
last seen2016-12-05
published2010-12-01
reporterMark Stanislav
sourcehttps://packetstormsecurity.com/files/96250/Orbis-CMS-1.0.2-Shell-Upload.html
titleOrbis CMS 1.0.2 Shell Upload

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:70302
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-70302
titleOrbis CMS 1.0.2 - Arbitrary File Upload Vulnerability