Directory traversal vulnerability in hpmpa/jobDelivery/Default.asp in HP Managed Printing Administration before 2.6.4 allows remote attackers to create arbitrary files via crafted form data.
http://www.zerodayinitiative.com/advisories/ZDI-11-354/
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03128469