Concrete5 prior to 8.5.3 allows Unrestricted Upload of File with Dangerous Type such as a .phar file.
concretecms concrete cms