This question is locked. New answers and comments are not allowed.
If you're using the upload component, please make sure that the folder you use for uploading (if it's underneath your application) does not have execute or execute script privileges. Otherwise, a user can upload an aspx file and execute it as part of your app.