csNews contains a flaw that will allow an attacker to execute arbitrary code. The problem is that the contents of text fields in the advanced settings are not verified properly and will allow an attacker to inject arbitrary perl code.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
OSVDB:
Web Related
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.