LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters.
LPAR2RRD in
Vulnerability
CVE-2014-4981
NVD
Refer to CVE-2014-4981 NVD advisory