"evaluatorComment":"Per: http://cwe.mitre.org/data/definitions/434.html\r\n\r\n'CWE-434: Unrestricted Upload of File with Dangerous Type'",
"descriptions":[
{
"lang":"en",
"value":"Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users to execute arbitrary code by uploading a .php file, and then accessing it via a direct request to the file in uploads/."
},
{
"lang":"es",
"value":"Vulnerabilidad de subida no restringida de ficheros en fileman_file_upload.php en CMS v1.0.2, permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n al subir un fichero .php, accediendo posteriormente mediante una petici\u00f3n directa del fichero en uploads/."