The media rename feature in GeniXCMS through 0.0.8 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to rename and execute files with the `.php6`, `.php7` and `.phtml` extensions.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/95460 | vdb entry third party advisory |
https://github.com/semplon/GeniXCMS/issues/62 | issue tracking patch exploit third party advisory |