An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows malicious users to execute arbitrary code via a crafted file.
houdunren hdcms 5.7