Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.
https://exchange.xforce.ibmcloud.com/vulnerabilities/20191
http://www.securityfocus.com/bid/13172