Sergey Korostel PHP Upload Center allows remote attackers to execute arbitrary PHP code by uploading a file whose name ends in a .php.li extension, which can be accessed from the upload directory.
http://www.vupen.com/english/advisories/2006/0817
http://www.securityfocus.com/archive/1/427215/100/0/threaded
http://www.scripts-by.net/PHP/File-Manipulation/php-upload-center.html