During a code review of the susehelp package the SuSE Security Team
recognized that the security checks done by the susehelp CGI scripts are
insufficient. Remote attackers can insert certain characters in CGI
queries to the susehelp system tricking it into executing arbitrary code as
the "wwwrun" user. Please note that this is only a vulnerability if you
have a web server running and configured to allow access to the susehelp
system by remote sites.