CVE-2006-5258

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
12/10/2006
Last modified:
09/04/2025

Description

The spell checking component of (1) Asbru Web Content Management before 6.1.22, (2) Asbru Web Content Editor before 6.0.22, and (3) Asbru Website Manager before 6.0.22 allows remote attackers to execute arbitrary commands via an unspecified parameter that is not sanitized before Aspell is invoked.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:asbru_software:asbru_web_content_management:*:*:*:*:*:*:*:* 6.1.20 (including)
cpe:2.3:a:asbru_software:asbru_web_content_management:6.0:*:*:*:*:*:*:*
cpe:2.3:a:asbru_software:asbru_web_content_management:6.0.17:*:*:*:*:*:*:*
cpe:2.3:a:asbru_software:asbru_web_content_management:6.1:*:*:*:*:*:*:*
cpe:2.3:a:asbru_software:asbru_web_content_management:6.1.19:*:*:*:*:*:*:*
cpe:2.3:a:asbru_software:asbru_website_manager:6.0.20:*:*:*:*:*:*:*