doesn't really seem to be a security flaw, but I get:
"Fatal error: Uncaught BitcoinClientException:
- : Didn't receive 200 OK from remote server. (HTTP/1.1 500 Internal Server Error) thrown in on line 0"
when I fill in 1 in the bitcoin field and 1 in the bitcoin address (rather than putting in a real bitcoin address)