In Samba versions 3.0.0 through 3.0.25rc3, unescaped user input parameters are passed as arguments to /bin/sh allowing for remote command execution.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/56718/smb-inject.txt
Source: https://packetstormsecurity.com/files/56718/smb-inject.txt.html

