A lack of variable sanitizing in PMachine online publishing tools allows for remote command execution as the webserver uid.