The launch method in the LocalExec ActiveX control (LocalExec.ocx) in Novell exteNd Director 4.1 and Portal Services allows remote attackers to execute arbitrary commands.Referenceshttp://osvdb.org/37318https://secure-support.novell.com/KanisaPlatform/Publishing/360/3169416_f.SAL_Public.htmlhttp://www.vupen.com/english/advisories/2007/2235https://exchange.xforce.ibmcloud.com/vulnerabilities/34898http://www.kb.cert.org/vuls/id/793433http://secunia.com/advisories/25710http://www.novell.com/documentation/nedse41/readmesp2.txthttp://www.securityfocus.com/bid/24493http://www.securitytracker.com/id?1018258