The WeOnlyDo! SFTP (wodSFTP) ActiveX control is marked as safe for scripting, which allows remote attackers to read and write files in arbitrary locations by accessing the control from a web page.
https://exchange.xforce.ibmcloud.com/vulnerabilities/26752
http://www.vupen.com/english/advisories/2006/2064
http://www.securityfocus.com/bid/18192