Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.
https://exchange.xforce.ibmcloud.com/vulnerabilities/39994
http://www.securityfocus.com/bid/17046
http://www.securityfocus.com/archive/1/427158/100/0/threaded