File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.
https://github.com/BoidCMS/BoidCMS/issues/27
http://packetstormsecurity.com/files/175026/BoidCMS-2.0.0-Shell-Upload.html