McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in a (1) TestFile XML element or the (2) hostname. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands.
https://exchange.xforce.ibmcloud.com/vulnerabilities/90162
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-6889
http://www.securityfocus.com/bid/64150