Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.
- http://packetstormsecurity.com/files/135721/Exponent-2.3.7-PHP-Code-Execution.html
No PoCs found on GitHub currently.