www file share pro 5.30 insecure multiple

this server that now has reached 5.30 per version still contains many elements of insecurity:

does not control the file extensions loaded
not figure the pass not esitone setting permits 666 777 etc.
Min poc:

