upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.
https://exchange.xforce.ibmcloud.com/vulnerabilities/22012
http://www.securityfocus.com/bid/14667