CVE-2020-35729
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
Date published : 2020-12-26
http://packetstormsecurity.com/files/160798/Klog-Server-2.4.1-Command-Injection.html
http://packetstormsecurity.com/files/161123/Klog-Server-2.4.1-Command-Injection.html