uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote malicious users to gain administrative privileges via a direct request.
abweb minimal-ablog 0.4