Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.Referenceshttp://seclists.org/fulldisclosure/2014/Oct/121https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-7178/https://www.tuleap.org/recent-vulnerabilities