Exponent CMS 0.96.3 and later versions does not properly restrict the types of uploaded files, which allows remote attackers to upload and execute PHP files.
https://exchange.xforce.ibmcloud.com/vulnerabilities/23113
http://www.securityfocus.com/bid/15391
http://www.securityfocus.com/archive/1/417218