support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator characters in the query string.Referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39182http://secunia.com/advisories/28182http://www.securityfocus.com/archive/1/485398/100/0/threadedhttp://osvdb.org/39875http://www.exploit-db.com/exploits/15987http://securityreason.com/securityalert/3480http://www.securityfocus.com/bid/26963