upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
https://github.com/YameenMunir/Systems-and-Cyber-Security-Coursework
https://exchange.xforce.ibmcloud.com/vulnerabilities/22012
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-2734
http://www.securityfocus.com/bid/14667