Summary

File upload logic is flawed, and allows an attacker to enable paths with traversals - similar problem as reported in