ans.pl in Avengers News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Avengers_news_system | Avengers_news_system | 2.01 (including) | 2.01 (including) |
Avengers_news_system | Avengers_news_system | 2.11 (including) | 2.11 (including) |