OneFileCMS
OneFileCMS copied to clipboard
onefilecms.php in OneFileCMS through 2017-10-09 might allow attackers to execute arbitrary PHP code via xxx .php filename on the Upload File screen
access http://fragrant:30001/OneFileCMS/onefilecms.php by username/password

Click Upload File -> abc.php -> Browse -> select abc.php -> Click Upload


access http://fragrant:30001/abc.php
