admin/upprocess.php in DGNews 1.5 and earlier allows remote attackers to execute arbitrary code by uploading scripts with arbitrary extensions to the img directory.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Dgnews |
Dgnews |
* |
1.5 (including) |
References