Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.
http://download.nai.com/products/licensed/pgp/hf3pki10.txt
http://archives.neohapsis.com/archives/bugtraq/2000-07/0473.html