CVE-2010-3313 describes a command injection vulnerability in EGroupware and EPL, specifically within the spellchecker.php script. Remote attackers can execute arbitrary commands by injecting shell metacharacters into the aspell_path or spellchecker_lang parameters. This vulnerability carries a CVSS score of 7.5, indicating high severity due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit code is publicly available via ExploitDB (EDB-11777), and it has garnered community discussion and media coverage, including its use by the Gitpaste-12 worm botnet.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.001CPE matchmatch criteria | cpe:2.3:a:egroupware:egroupware:1.4.001:*:*:*:*:*:*:* | ||
1.4.001\+.002CPE matchmatch criteria | cpe:2.3:a:egroupware:egroupware:1.4.001\+.002:*:*:*:*:*:*:* | ||
1.4.002CPE matchmatch criteria | cpe:2.3:a:egroupware:egroupware:1.4.002:*:*:*:*:*:*:* | ||
1.6.001CPE matchmatch criteria | cpe:2.3:a:egroupware:egroupware:1.6.001:*:*:*:*:*:*:* | ||
1.6.001\+.002CPE matchmatch criteria | cpe:2.3:a:egroupware:egroupware:1.6.001\+.002:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.