Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php via the get_login_ip_config_file function.
View the template here CVE-2014-1203.yaml
References:
https://github.com/ARPSyndicate/cvemon