Format string vulnerability in Imendio Planner 0.13 allows user-assisted attackers to execute arbitrary code via format string specifiers in a filename.
http://www.securityfocus.com/bid/19307
http://www.securityfocus.com/archive/1/442439/100/0/threaded