File upload with absolute path, denial of service, crossite scripting.
vulners.com/securityvulns/securityvulns:doc:11765