It's possiblt to execute application on server by specifing '|' in filename.
vulners.com/securityvulns/securityvulns:doc:6339