Unrated severityNVD Advisory· Published Apr 22, 2010· Updated Apr 29, 2026
CVE-2009-4793
CVE-2009-4793
Description
Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to adminpanel/index.php, and then accessing the file via a direct request with an images/gallery/ directory name. NOTE: some of these details are obtained from third party information.
Affected products
1- cpe:2.3:a:karl_core:bandsite_cms:1.1.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- secunia.com/advisories/21992nvdVendor Advisory
- www.exploit-db.com/exploits/8309nvd
News mentions
0No linked articles in our index yet.