users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Boastmachine | Boastmachine | 3.0 (including) | 3.0 (including) |