Make sure /admin/htmlarea/popups/file/ is protected from access from just anyone. From looking into the code. I think it will allow just anyone to upload files. If you dont need it just remove the directory.

More...