H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request.
http://www.securitytracker.com/id?1005893
http://www.securityfocus.com/bid/6539
http://www.securityfocus.com/bid/6537
http://www.securityfocus.com/archive/1/305313