CVE-2006-0658
N/A
N/A
Summary
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://retrogod.altervista.org/fckeditor_22_xpl.html
- http://www.vupen.com/english/advisories/2006/0502
- http://www.securityfocus.com/archive/1/424708
- http://secunia.com/advisories/18767
- https://www.exploit-db.com/exploits/3702
References
- http://retrogod.altervista.org/fckeditor_22_xpl.html
- http://www.vupen.com/english/advisories/2006/0502
- http://www.securityfocus.com/archive/1/424708
- http://secunia.com/advisories/18767
- https://www.exploit-db.com/exploits/3702
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.