includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0690
http://www.securityfocus.com/bid/12738