He couldn't use it unless he knew the URL to the file and smf doesn't allow direct file linking like that hence the sequence of numbers on the download files. It doesn't allow code execution that way either. It was used to hack smf a while back. So yes it's safe to upload it as an attachment. What a boring day...:p