Description
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the argv[1] parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin U Extended Comment 'fileurl' Parameter Arbitrary File Download (1.0.1)
MySQL CVE-2019-2969 Vulnerability (CVE-2019-2969)
WordPress Plugin SRS Simple Hits Counter SQL Injection (1.0.4)
WordPress Plugin Bold Timeline Lite Cross-Site Scripting (1.1.4)
WordPress Plugin Custom Post Type UI Cross-Site Request Forgery (1.7.3)