BigTree version 4.2.8 suffers from object injection and improper filename sanitization. Continue reading...