aspell_setup.php in the SpellChecker plugin in DTLink AreaEdit before 0.4.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the dictionary parameter (aka the lang variable).
References
| Link | Resource |
|---|---|
| http://www.formvista.com/otherprojects/areaedit | Patch |
| http://secunia.com/advisories/16511 | Patch Vendor Advisory |
| http://www.formvista.com/forum.html?COMP=forum&cmd=view_thread&(fvs)cs_forums_threads_ref=47 |
Configurations
Information
Published : 2005-08-22 21:00
Updated : 2018-08-13 14:47
NVD link : CVE-2005-2682
Mitre link : CVE-2005-2682
JSON object : View
CWE
Products Affected
dtlink
- areaedit


