blitzen.. i will try do disable upload functions too, but this is not the only problem in my opinion.
i dont know if i was a to much freak about security stuff, but this bug permit anyone to list all users in hcl system...
and for me this is not good thing.... all we know, common users are not good to create and use strong passwords....
so if i was tryng to hacking something after discover all users name, i can try to break passwords from users and loged in like a real operator... this is make me really apreensive...
think about it... someone log in your system and talk with yout customers like a real operator ?!!!!!!

but i?m will not quit hcl totally... its a good tool but needs to be repared.... so until we had some response from hcl dev team about this bug i suggest you to check crafty syntax too....im testing this tool yet, but it appears a little more robust about security things....
that is it people... sorry about my poor english...
alaor