Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr.
- http://packetstormsecurity.com/files/171489/Composr-CMS-10.0.39-Remote-Code-Execution.html
- https://github.com/cnnrshd/bbot-utils