The calender.pl and the calendar_admin.pl calendar scripts by Matt Kruse allow remote malicious users to execute arbitrary commands via shell metacharacters.
source: wwwsecurityfocuscom/bid/1215/info
Matt Kruse's Calendar script is a popular, free perl cgi-script used by many websites on the Internet It allows a website administrator to easily setup and customize a calendar on their website There are two components of this package, calendar-adminpl and calendarpl Calendar-adminpl calls o ...