See how spug compares to other vendors in security performance
Spug through 3.4.0 contains a remote code execution vulnerability in the pingcheck function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the /monitor/runtest/ endpoint to execute arbitrary commands as the Spug process user.