If you are running CodeIgniter 1.7.2, there is a security flaw with the file upload class. (fixed on July 12, 2010) The easiest way to install the patch is to use the standalone patch http://codeigniter.com/download_files/CI_1.7.2_201007_sec_patch.zip and unzip the file to the Code Igniter system/libraries folder.