IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.
IRIS citations management tool
Exploit
CVE-2013-1744
NVD
Refer to CVE-2013-1744 NVD advisory