Users of 'Orbis CMS' please be advised of an Arbitrary Script Execution vulnerability that has been identified.
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)
Amplify’d from www.criticalwatch.com
Orbis-SA-11/29/2010: 'Orbis CMS' Arbitrary Script Execution Vulnerability (CVE-2010-4313)
DESCRIPTIONRead more at www.criticalwatch.com
---------------------------------------
A vulnerability exists in the 'Orbis CMS' fileman_file_upload.php script that allows any authenticated user to upload a
PHP script and then run it without restriction.
See this Amp at http://bit.ly/gEARXY
No comments:
Post a Comment