How does he know your URL becasue you have to access the file with some other id, like give the id to the file which is uploaded . But some risk is of ´course there. He does not know in whcih directory it is uploaded. SOne risk is always there but you can track using his ip address when it is uploaded