DTLink Software AreaEdit SpellChecker Plugin Arbitrary Command Execution Vulnerability
BID:14627
Info
DTLink Software AreaEdit SpellChecker Plugin Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 14627 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2005 12:00AM |
| Updated: | Aug 22 2005 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
DTLink Software AreaEdit 0.4.2 DTLink Software AreaEdit 0.4.1 |
| Not Vulnerable: |
DTLink Software AreaEdit 0.4.3 |
Discussion
DTLink Software AreaEdit SpellChecker Plugin Arbitrary Command Execution Vulnerability
AreaEdit is affected by a remote arbitrary command execution vulnerability.
Successful exploitation of this issue results in command execution with the privileges of the Web server process. This can lead to various attacks including unauthorized access to an affected computer.
AreaEdit versions prior to 0.4.3 are affected by this vulnerability.
AreaEdit is affected by a remote arbitrary command execution vulnerability.
Successful exploitation of this issue results in command execution with the privileges of the Web server process. This can lead to various attacks including unauthorized access to an affected computer.
AreaEdit versions prior to 0.4.3 are affected by this vulnerability.
Exploit / POC
DTLink Software AreaEdit SpellChecker Plugin Arbitrary Command Execution Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
DTLink Software AreaEdit SpellChecker Plugin Arbitrary Command Execution Vulnerability
Solution:
The vendor has released AreaEdit 0.4.3 to address this issue.
DTLink Software AreaEdit 0.4.1
DTLink Software AreaEdit 0.4.2
Solution:
The vendor has released AreaEdit 0.4.3 to address this issue.
DTLink Software AreaEdit 0.4.1
-
DTLink Software areaedit_0.4.3.tar.gz
http://freshmeat.net/redir/areaedit/58526/url_tgz/areaedit_0.4.3.tar.g z
DTLink Software AreaEdit 0.4.2
-
DTLink Software areaedit_0.4.3.tar.gz
http://freshmeat.net/redir/areaedit/58526/url_tgz/areaedit_0.4.3.tar.g z
References
DTLink Software AreaEdit SpellChecker Plugin Arbitrary Command Execution Vulnerability
References:
References:
- AreaEdit Product Page (DTLink Software)