An attacker can exploit these issues to upload arbitrary code and execute it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Remote Bypass Authentication
All form in directory [Sisfokol]/janissari/k/ does not require authentication to upload a file. By issuing a POST request with a webshell embedded in a JPEG image it is possible to upload [Sisfokol]/filebox/