Debian Security Advisory 1825-1 – It was discovered that the statuswml.cgi script of nagios, a monitoring and management system for hosts, services and networks, is prone to a command injection vulnerability. Input to the ping and traceroute parameters of the script is not properly validated which allows an attacker to execute arbitrary shell commands by passing a crafted value to these parameters.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/78921/dsa-1825-1.txt
Source: https://packetstormsecurity.com/files/78921/Debian-Linux-Security-Advisory-1825-1.html

