I found a BUG located in "Configuration -> General -> Images", which isn't fixed a.f.a.k. until now in version pre-1.5 (i checked the ChangeLog).
If the uploaded file is no image, no error is shown. So I was able to upload *.doc, *.pdf, *.exe. I think, that only *.gif, *.jpg, *.tif, *.png should be allowed there.
If the uploaded file is no image, no error is shown. So I was able to upload *.doc, *.pdf, *.exe. I think, that only *.gif, *.jpg, *.tif, *.png should be allowed there.