Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files.
- http://securityreason.com/securityalert/3842
- https://www.exploit-db.com/exploits/5478
No PoCs found on GitHub currently.