If you allow %s, any ISAPI extension can run on your Web server. This is a potential security risk. Do you want to allow ...