CVE-2006-5258
Summary
| CVE | CVE-2006-5258 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-10-12 22:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The spell checking component of (1) Asbru Web Content Management before 6.1.22, (2) Asbru Web Content Editor before 6.0.22, and (3) Asbru Website Manager before 6.0.22 allows remote attackers to execute arbitrary commands via an unspecified parameter that is not sanitized before Aspell is invoked. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Asbru Software | Asbru Website Manager | 6.0.20 | All | All | All |
| Application | Asbru Software | Asbru Web Content Management | 6.0 | All | All | All |
| Application | Asbru Software | Asbru Web Content Management | 6.0.17 | All | All | All |
| Application | Asbru Software | Asbru Web Content Management | 6.1 | All | All | All |
| Application | Asbru Software | Asbru Web Content Management | 6.1.19 | All | All | All |
| Application | Asbru Software | Asbru Web Content Management | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| PageHeader($myrequest->getParameter("id"), "title", "")) ?> | af854a3a-2127-422b-91ae-364da2661108 | editor.asbrusoft.com | |
| Asbru Web Content Editor Shell Command Injection - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| PageHeader($myrequest->getParameter("id"), "title", "")) ?> | af854a3a-2127-422b-91ae-364da2661108 | wcm.asbrusoft.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| archives.neohapsis.com/archives/fulldisclosure/2006-10/0306.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| Asbru Website Manager Shell Command Injection - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Asbru Software Web Content Editor Shell Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Asbru Web Content Management Shell Command Injection - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.