Vulnerability profile:
In edit blog template, we can control the website system by writing PHP executable code and running malicious code
Test environment: PHP version 5.6.2 +appach
Affected version
<=3.0.4
Vulnerability details:
- Use the administrative user to log in to the website: http://ip:port/monstra/admin/index.php?id=themes&action=edit_ template&filename=blog
2.Write PHP executable code in template content

3.Save the modified template content,visit:http://ip:port/monstra/blog
Get shell and control the website
