Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and execute PHP files.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/15391 | vdb entry |
http://www.securityfocus.com/archive/1/417218 | vendor advisory mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/23113 | vdb entry |
http://secunia.com/advisories/17655 | third party advisory vendor advisory |
http://secunia.com/advisories/17505 | third party advisory |