Description
e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg content type.
Remediation
References
Related Vulnerabilities
CrushFTP Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2018-18288)
WordPress Plugin iCopyright Toolbar 'icopyright_xml.php' SQL Injection (1.1.4)
WordPress Plugin RSVPMaker SQL Injection (9.2.6)
WordPress Plugin Category List Portfolio Page TimThumb Arbitrary File Upload (1.2.3)