upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Simple_php_blog | Alexander_palmo | 0.4.0 (including) | 0.4.0 (including) |