An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files…
Link: http://feeds.security-database.com/~r/Last100Alerts/~3/uyZp0bQpvGI/detail.php