Halo Blog CMS v1.4.17 exists to allow malicious users to upload arbitrary files via the Attachment Upload function.
halo halo 1.4.17