Crossite scripting, directory traversal on file upload, information leak.
vulners.com/securityvulns/securityvulns:doc:4183