> The main problem is having effectively web-accessible content in the > web root. It's virtually a flat-out "don't ever do it".
I agree. But there have been parent path escaping issues in the past that allow attackers to reference files outside of the web root even. A bit more clarity around this part of the exploit would be more helpful.
