Latest exploit, public 13. feb 2010
Please check out the link and post your comments... is this bug still in later versions than v1.0 ?

Can't get it to work on a 1.7 install thanks to the "no direct script access allowed" header in every non-controller file.