Vulnerable Systems:
* appRain appRain CMF 0.1.5 and prior
An attacker may leverage this issue to upload arbitrary files to the affected server; this can result in arbitrary code execution within the context of the vulnerable application.
appRain CMF could allow a remote attacker to upload arbitrary files, caused by the improper validation of file extensions by the uploadify.php script. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to upload a malicious PHP script, which could allow the attacker to execute arbitrary PHP code on the vulnerable system.