Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors.
http://www.securityfocus.com/bid/34206
http://www.debian.org/security/2009/dsa-1752
http://www.citadel.org/doku.php/news:webcit.security.advisory.-.2009-march-23