The launch method in the LocalExec ActiveX control (LocalExec.ocx) in Novell exteNd Director 4.1 and Portal Services allows remote attackers to execute arbitrary commands.
https://secure-support.novell.com/KanisaPlatform/Publishing/360/3169416_f.SAL_Public.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/34898
http://www.vupen.com/english/advisories/2007/2235
http://www.securitytracker.com/id?1018258
http://www.novell.com/documentation/nedse41/readmesp2.txt
http://www.kb.cert.org/vuls/id/793433