Highlighted vulnerable code.
Authenticated user can select a php file (shell.php in example) when publishing news
And by intercepting and editing the content-type header of the request to a valid type (image/jpeg) in example.
The php file is uploaded to the /allpostpics/ folder
Which leads to code execution





