Open WorkFlow Engine version 1.4.x allows for cross site scripting attacks and to be used as a port scanner.