preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by the Status::admin command, which causes the Status line to be entered into the password file.
Score: 3.0
Priority: P2 - Serious (High)
Score: 0.01193
Percentile:
0.77966
CVSS v2 Score: 10.0
Severity: