CVE-2006-0658
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the…
Does this matter?
Lower severity and a low EPSS score (6.90%). Track it; it rarely justifies an emergency change on its own.
Description
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 6.90% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- fckeditor/fckeditor
- Source
- cve@mitre.org
References
- http://retrogod.altervista.org/fckeditor_22_xpl.htmlExploit
- http://secunia.com/advisories/18767Vendor Advisory
- http://www.securityfocus.com/archive/1/424708Exploit
- http://www.vupen.com/english/advisories/2006/0502Vendor Advisory
- https://www.exploit-db.com/exploits/3702
- http://retrogod.altervista.org/fckeditor_22_xpl.htmlExploit
- http://secunia.com/advisories/18767Vendor Advisory
- http://www.securityfocus.com/archive/1/424708Exploit
- http://www.vupen.com/english/advisories/2006/0502Vendor Advisory
- https://www.exploit-db.com/exploits/3702
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.