CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation.
https://exchange.xforce.ibmcloud.com/vulnerabilities/18998
http://securitytracker.com/id?1012951