RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files via unspecified vectors.
https://www.exploit-db.com/exploits/4971
http://www.securitytracker.com/id?1019267
http://www.securityfocus.com/bid/27420
http://www.securityfocus.com/bid/27419
http://www.securityfocus.com/archive/1/486868/100/0/threaded