CVE-2016-7095
Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected folder, one allowing script execution.
Date published : 2016-11-03
http://www.securityfocus.com/bid/94121
http://www.exponentcms.org/news/security-vulnerability-all-exponent-versions-june-2016
