Bodington 2.1.0 RC1 and earlier does not secure the file upload area, which allows remote attackers to read uploaded files.
https://exchange.xforce.ibmcloud.com/vulnerabilities/14986
http://www.securityfocus.com/bid/9528
http://www.secunia.com/advisories/10749/
http://sourceforge.net/tracker/index.php?func=detail&aid=789761&group_id=87659&atid=583930