Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files.
https://www.exploit-db.com/exploits/5478
https://exchange.xforce.ibmcloud.com/vulnerabilities/41922
http://www.securityfocus.com/archive/1/491129/100/0/threaded