This is not an exploit...
Face it...
Its just simply using a different interface to access the files.
Your not able to do something that you shouldn't be able to do, which is really what an exploit is...

Now, if you could upload to their computer through this method... I'd say its an exploit... but you can't.... so I won't..

I'd be hard pressed to bring myself to admit this is a security flaw... the closest this comes to being a security flaw, is that you can get the users IP Address... and that is unavoidable in a P2P situation AFAIK...