Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and execute PHP files.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Exponent | Exponent | 0.94 (including) | 0.94 (including) |
| Exponent | Exponent | 0.95 (including) | 0.95 (including) |
| Exponent | Exponent | 0.96.1 (including) | 0.96.1 (including) |
| Exponent | Exponent | 0.96.3 (including) | 0.96.3 (including) |
| Exponent | Exponent | 0.96.4 (including) | 0.96.4 (including) |