Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.
https://exchange.xforce.ibmcloud.com/vulnerabilities/89669
http://www.securityfocus.com/bid/64258
http://www.openwall.com/lists/oss-security/2013/12/13/2