7.5
CVSSv2

CVE-2010-3313

Published: 22/09/2010 Updated: 18/08/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

phpgwapi/js/fckeditor/editor/dialog/fck_spellerpages/spellerpages/serverscripts/spellchecker.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versions prior to 1.6.003; and EPL 9.1 prior to 9.1.20100309 and 9.2 prior to 9.2.20100309; allows remote malicious users to execute arbitrary commands via shell metacharacters in the (1) aspell_path or (2) spellchecker_lang parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

egroupware egroupware 1.6.001\\+.002

egroupware egroupware 1.6.001

egroupware egroupware 9.1

egroupware egroupware 1.6.002

egroupware egroupware 1.4.001

egroupware egroupware 1.4.002

egroupware egroupware 9.2

egroupware egroupware 1.4.001\\+.002

Exploits

Advisory Name: Remote Command Execution in EGroupware Vulnerability Class: Remote Command Execution Release Date: 2010-03-09 Affected Applications: Confirmed in EGroupware 14001+002 and 16001+002 EGroupware Premium Line 91 and 92 is also affected Other versions may also be affected Affected Platforms: Multiple Local / Remote: Remot ...