wordtrans 1.1pre8 and earlier in the wordtrans-web package allows remote attackers to (1) execute arbitrary code or (2) conduct cross-site scripting attacks via certain parameters (possibly "dict") to the wordtrans.php script.
| Software | From | Fixed in |
|---|---|---|
| wordtrans / wordtrans-web | 1.1_pre8 | 1.1_pre8.x |
| wordtrans / wordtrans-web | 1.0_beta2.2.4 | 1.0_beta2.2.4.x |