File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://boidcms.com | product |
https://github.com/BoidCMS/BoidCMS/issues/27 | vendor advisory issue tracking exploit |
http://packetstormsecurity.com/files/175026/BoidCMS-2.0.0-Shell-Upload.html |