The citat.pl script allows remote attackers to execute arbitrary files via shell metacharacters in the argument.
CVSS Metrics