I took a shot at writing an exploit for this, so here goes. Choice of WinExec(the calculator, what else?) or a bindshell.
-------------------------------
Persits Software XUpload Control AddFolder BoF Exploit
-------------------------------
Elazar
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/