See how klogserver compares to other vendors in security performance
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shellexec() on the original value of the source parameter.
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.