Secunia Research has discovered a vulnerability in Pulse CMS, which can be exploited by malicious users to compromise a vulnerable system. An error in the validation of uploaded image files can be exploited to upload files with an arbitrary extension to a folder within the web root. This can be exploited to upload and execute arbitrary PHP code. Successful exploitation requires authentication. Pulse CMS basic versions 1.2.2 and 1.2.3 are affected.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/88205/secunia-pulsecms.txt
Source: https://packetstormsecurity.com/files/88205/Pulse-CMS-Arbitrary-File-Upload.html