webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."
https://hermes.opensuse.org/messages/7797670
https://euvd.enisa.europa.eu/vulnerability/EUVD-2011-0476
http://secunia.com/advisories/43960