Nice find. File upload is always scarily dangerous when unprotected.
Andy Tyler

100% agree with your comment. One more thing, if you ever do this again or for a living, get it all in writing as well. Permission in relation to the scope of the pen test, is extremely important, or you could end up in legal/financial trouble despite your good intentions. Other than that great job.

