calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the command parameter.
CVE Status: Modified
No CVSS data available
Exploit-db Github