The first flaw is due to errors in the "WZFILEVIEW.FileViewCtrl.61" ActiveX control that does not validate input passed to CreateNewFolderFromName methods,When you pass a long string(length>235),It will bead to buffer overflow .which could be exploited by remote attackers to execute arbitrary comman...
[ more ]