vendor:
                    Papoo CMS
                by:
                    RedTeam Pentesting
                5.5
                        CVSS
                    MEDIUM
                    Authenticated Arbitrary Code Execution
                    TBA
                        CWE
                    Product Name: Papoo CMS
                    Affected Version From:  3.7.2003
                    Affected Version To:  3.7.2003
                    Patch Exists: YES
                    Related CWE: TBA
                    CPE:  papoo-cms
                    Platforms Tested:  
                    2009
                    Papoo CMS: Authenticated Arbitrary Code Execution
The Papoo CMS allows authenticated users to upload GIF, JPG and PNG images if they have the "upload images" privilege, which is true for all default groups that can access the administrative interface. The CMS checks the uploaded images only for their header, but not for the file extension. It is therefore possible to upload images with the file extension ".php" and a valid image header. By embedding PHP code into the image (e.g. by using the GIF comments field), arbitrary code can be executed when requesting the image.
Mitigation:
					Applying the vendor patch for version 3.7.3.