LXR version 1.0.0 to 2.3.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.Referenceshttp://jvn.jp/en/jp/JVN72589538/index.htmlhttp://lxr.sourceforge.net/en/bugsandlimits.php