LokiCMS versions 0.3.4 and below suffer from arbitrary file overwrite, code injection, file inclusion, and administrative hash retrieval vulnerabilities.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/66870/lokicms-multi.txt
Source: https://packetstormsecurity.com/files/66870/lokicms-multi.txt.html

