Two OS command injection flaws can be exploited remotely, without authentication, for arbitrary code execution.