Arbitrary Command Execution in DTLink AreaEdit SpellChecker Plugin

Arbitrary Command Execution in DTLink AreaEdit SpellChecker Plugin

CVE-2005-2682 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

aspell_setup.php in the SpellChecker plugin in DTLink AreaEdit before 0.4.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the dictionary parameter (aka the lang variable).

Learn more about our Web Application Penetration Testing UK.