Description
Concrete5 up to and including 8.5.2 allows Unrestricted Upload of File with Dangerous Type such as a .php file via File Manager. It is possible to modify site configuration to upload the PHP file and execute arbitrary commands.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2007-2110 Vulnerability (CVE-2007-2110)
WordPress Plugin DW Question & Answer Multiple Unspecified Vulnerabilities (1.4.4)
Dotclear Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3232)
WordPress 'wp-trackback.php' SQL Injection Vulnerability (1.5)
WordPress Plugin WordPress Photo Gallery by Gallery Bank SQL Injection (3.0.229)