Products

Showing 2 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
fckeditor vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

fckeditor fckeditor Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

CWE-22Jul 5, 2009
CVSS7.5v2.0EPSS83.9%PoCs10SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

FCKeditor before 2.3 Beta editor/filemanager/upload/php/upload.php Arbitrary File Upload

editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658.

May 22, 2006
CVSS5.0v2.0EPSS2.42%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX