Security BigTree 4.2.8 Object Injection / Improper Filename Sanitization March 18, 2016 007admin Leave a comment BigTree version 4.2.8 suffers from object injection and improper filename sanitization.