core/spellcheck/spellcheck.php in Fundanemt prior to 2.2.0.1 allows remote malicious users to execute arbitrary commands via shell metacharacters in the dict parameter.
fundanemt fundanemt