It's possible that users that uses Pizco were vulnerable to the same vulnerability that "Aurigma ImageUploader4.ocx" that found Elazar Broad. This post is this: The version of ImageUploader4 is And I say that it's possible because I find a site where I download it, but I don't saw where the Activex control is used. Web with the vulnerable control: