The following proof of concept works on Firefox 2.0.0.3 with Firebug 1.01. Other setups might be vulnerable too.

Test Description
the following test executes calc.exe
the following test executes cmd.exe
!!! don't click