Multiple vulnerabilities have been identified in CMS-Bandits, which could be exploited by attackers to execute arbitrary commands. These flaws are due to input validation errors in the "dialogs/img.php" and "dialogs/td.php" scripts that do not validate the "spaw_root" parameter, which could be exploited by remote attackers to include malicious scripts and execute arbitrary commands with the privileges of the web server.
Vulnerable Products
Vulnerable Software: CMS-Bandits version 2.5 and prior