CVE-2007-5156
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 8.00% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- cardinal cms project/cardinal cms · redlinesoft/lanai cms · sitex cms project/sitex cms · syntax cms project/syntax cms
- Source
- cve@mitre.org
References
- http://dev.fckeditor.net/changeset/973Vendor Advisory
- http://dev.fckeditor.net/ticket/1325Vendor Advisory
- http://downloads.securityfocus.com/vulnerabilities/exploits/30677.phpBroken Link
- http://secunia.com/advisories/27123Third Party Advisory
- http://secunia.com/advisories/27174Third Party Advisory
- http://securityreason.com/securityalert/3182Exploit, Third Party Advisory
- http://sourceforge.net/forum/forum.php?forum_id=743930Broken Link
- http://sourceforge.net/project/shownotes.php?release_id=546000Broken Link
- http://www.securityfocus.com/archive/1/480830/100/0/threadedExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29422Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30677Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/3464Third Party Advisory
- http://www.vupen.com/english/advisories/2007/3465Third Party Advisory
- http://www.waraxe.us/advisory-57.htmlExploit, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42425Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42733Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44455Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/5618Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/5688Exploit, Third Party Advisory, VDB Entry
- http://dev.fckeditor.net/changeset/973Vendor Advisory
- http://dev.fckeditor.net/ticket/1325Vendor Advisory
- http://downloads.securityfocus.com/vulnerabilities/exploits/30677.phpBroken Link
- http://secunia.com/advisories/27123Third Party Advisory
- http://secunia.com/advisories/27174Third Party Advisory
- http://securityreason.com/securityalert/3182Exploit, Third Party Advisory
- http://sourceforge.net/forum/forum.php?forum_id=743930Broken Link
- http://sourceforge.net/project/shownotes.php?release_id=546000Broken Link
- http://www.securityfocus.com/archive/1/480830/100/0/threadedExploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29422Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30677Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.