Unfiltered characters in filename allow code execution.
vulners.com/securityvulns/securityvulns:doc:11240
vulners.com/securityvulns/securityvulns:doc:11241