Description
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the argv[1] parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Console Security Bypass (0.3.9)
WordPress Plugin SpiderCatalog Unspecified Vulnerability (1.6.8)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Cross-Site Scripting (6.4.2)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4569)