BitDefender's online scanning service has Active-X related flaws that allow an attacker to run arbitrary code server side.