The image upload feature in Tiki CMS/Groupware (TikiWiki) 1.8.1 and earlier allows remote attackers to upload and possibly execute arbitrary files via the img/wiki_up URL.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15849
http://tikiwiki.org/tiki-read_article.php?articleId=66