Hiverr contains a flaw that allows a remote user to execute arbitrary code. This flaw exists because the profilesetting.php script does not properly verify or sanitize user-uploaded profile image files. By uploading a specially crafted profile image file, the remote system will place the file in a user-accessible path. Making a direct request to the uploaded file will allow the user to execute the script with the privileges of the web server.