Directory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary code via vectors involving an HTML document on the server.
https://exchange.xforce.ibmcloud.com/vulnerabilities/74388
http://www.us-cert.gov/control_systems/pdf/ICSA-12-083-01.pdf