Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.
http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059788.html
http://secunia.com/advisories/28562
http://securityreason.com/securityalert/3570
http://www.securityfocus.com/archive/1/486722/100/0/threaded
http://www.securityfocus.com/bid/27363
http://www.vupen.com/english/advisories/2008/0237