Unrestricted Upload of File with Dangerous Type
An unrestricted file upload vulnerability in the jQuery File Upload Plugin server/php/UploadHandler.php allows remote attackers to execute arbitrary code by uploading a PHP file with an PHP extension. This file is then accessible via a direct request to the file in files/.