A flaw in phpMyFaq version 1.4.0 allows malicious users the ability to upload or delete arbitrary images.