ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.
| Software | From | Fixed in |
|---|---|---|
| avengers_news_system / avengers_news_system | 2.11 | 2.11.x |
| avengers_news_system / avengers_news_system | 2.01 | 2.01.x |