Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0524
http://www.securityfocus.com/bid/12635
http://www.securiteam.com/exploits/5WP082KEUW.html