aspell_setup.php in the SpellChecker plugin in DTLink AreaEdit before 0.4.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the dictionary parameter (aka the lang variable).
References
Configurations
History
21 Nov 2024, 00:00
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/16511 - Patch, Vendor Advisory | |
References | () http://www.formvista.com/forum.html?COMP=forum&cmd=view_thread&%28fvs%29cs_forums_threads_ref=47 - | |
References | () http://www.formvista.com/otherprojects/areaedit - Patch |
Information
Published : 2005-08-23 04:00
Updated : 2024-11-21 00:00
NVD link : CVE-2005-2682
Mitre link : CVE-2005-2682
CVE.ORG link : CVE-2005-2682
JSON object : View
Products Affected
dtlink
- areaedit
CWE