Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files.Referenceshttp://bugreport.ir/index.php?/36http://securityreason.com/securityalert/3842http://www.securityfocus.com/archive/1/491129/100/0/threadedhttp://www.securityfocus.com/bid/28868https://www.exploit-db.com/exploits/5478https://exchange.xforce.ibmcloud.com/vulnerabilities/41922