a73a7531a9
This is an authenticated RCE against BoidCMS versions 2.0.0 and earlier. The underlying issue is that the file upload check allows a php file to be uploaded and executes as a media file if the GIF header is present in the PHP file.