aspell_setup.php in the SpellChecker plugin in DTLink AreaEdit before 0.4.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the dictionary parameter (aka the lang variable).
Link | Tags |
---|---|
http://www.formvista.com/otherprojects/areaedit | patch |
http://www.formvista.com/forum.html?COMP=forum&cmd=view_thread&%28fvs%29cs_forums_threads_ref=47 | |
http://secunia.com/advisories/16511 | third party advisory patch vendor advisory |