TL;DR I use a race condition to upload two avatars at the same time to exploit another Paperclip bug and get remote code execution on Apache+Rails stacks. I believe many file uploaders are vulnerable to this.
more here.........http://homakov.blogspot.gr/2014/11/hacking-file-uploaders-with-race.html
more here.........http://homakov.blogspot.gr/2014/11/hacking-file-uploaders-with-race.html