|
Due to insufficient sanitization of user-supplied input in vpasswd.cgi, it is possible to pass arbitrary commands to the os.system() function. Exploiting this vulnerability allows a potential intruder to execute arbitrary system commands with the permissions of the web server.
|