The System Control Panel (SysCP) suffers from a flaw that allows an attack the ability to inject and execute any code as root. Versions 1.2.15 and below are affected. Details provided.
SEC Consult Security Advisory 20070226-0 - The 3rd party module Pagesetter for PostNuke is susceptible to a local file inclusion vulnerability. Versions 6.2.0 and 6.3.0 beta 5 are affected.