phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
- https://github.com/blindkey/cve_like/issues/4
- https://github.com/Live-Hack-CVE/CVE-2020-22201