The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15486
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-1764
http://www.securityfocus.com/bid/9855
http://www.kb.cert.org/vuls/id/831534