SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-0658

Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the…

MEDIUM 5.0EPSS 6.90%

Does this matter?

Lower severity and a low EPSS score (6.90%). Track it; it rarely justifies an emergency change on its own.

Description

Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
6.90% probability · 94th percentile
CISA KEV
Not listed
Affected
fckeditor/fckeditor
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.