Free Blog contains a flaw that allows a remote user to execute arbitrary code. This flaw exists because the up.php script does not properly verify or sanitize user-uploaded files. By uploading a specially crafted file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script with the privileges of the web server.
Proof of concept:
Arbitrary File Upload Vulnerability
http://bastardlabs/blog_path/up.php
Shell will be available here
http://bastardlabs/blog_path/log/images/shell.php
Disclosure Timeline:
Disclosure Date :2013-01-09
Exploit Publish Date :2013-01-09