If you're using the upload component, please make sure that the folder you use for uploading (if it's underneath your application) does not have execute or execute script privileges. Otherwise, a user can upload an aspx file and execute it as part of your app.