Berkeley finger.cgi has a remote command execution vulnerability because it does not strip out newlines.