users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Boastmachine | Boastmachine | 3.0 (including) | 3.0 (including) |