As someone who's written software for all his life, I'll posit that most "software engineers" write code like this. People don't test corner cases; they just shit out code, check that it works in the browser, and ship it. That's why the regexes like /.PNG/ are in there: they work, but they don't prevent the security problems they intend to prevent. If the engineer writing the code had written unit tests that checked various filenames, he would have discovered the bug immediately. If there were code reviews by someone who knew even the tiniest bit of Perl, the `$user_controlled_command > file` bug would be gone. If the programmer had run Perl with taint mode enabled, he would have discovered this bug instantly.
I think it's a mental thing: most people writing code never think "how could this go wrong", since they assume that they don't make mistakes. If you don't have a healthy fear of the code you write, you're not going to test the corner cases or not write complex features.
Ultimately, I'm not complaining, because buggy software is great in the context of devices that try to prevent you from doing something with your own property. I especially encourage people to write their system-level software in C and use lots of strcpy calls. It ensures that I can root my phone even though the carrier doesn't want me to.