Forum Moderators: phranque
For example: someone could upload a html file with a .jpg extension and Internet Explorer would then show the html file contents as coming from your site.
Also, do not trust the Mime type the user's browser sends when uploading a file, it can be faked. If a hole is left, someone could comprise your server.
Look for mime type exploit on google to read more on this.