Description
Concrete5 before 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
Remediation
References
Related Vulnerabilities
WordPress Plugin ActiveCampaign-Forms, Site Tracking, Live Chat Cross-Site Request Forgery (8.0.1)
PHP error logging format string vulnerability
Joomla Improper Input Validation Vulnerability (CVE-2015-8562)
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1914)