vendor:
eGroupWare
by:
Berk KIRAS
9.8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: eGroupWare
Affected Version From: 1.14
Affected Version To: 1.14
Patch Exists: YES
Related CWE: N/A
CPE: a:egroupware:egroupware:1.14
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Apache
2020
eGroupWare 1.14 – ‘spellchecker.php’ Remote Command Execution
eGroupWare 1.14 is vulnerable to Remote Command Execution. An attacker can send a specially crafted request to the spellchecker.php script in order to execute arbitrary commands on the vulnerable system. The script is located in the fck_spellerpages/spellerpages/server-scripts/ directory. The attacker can send a specially crafted request to the spellchecker.php script in order to execute arbitrary commands on the vulnerable system.
Mitigation:
Upgrade to the latest version of eGroupWare 1.14