Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://blog.topsec.com.cn/textpattern-background-any-file-upload/ | third party advisory exploit |