fckeditor Vulnerabilities and Affected Products
Vulnerabilities associated with fckeditor.
Products
Clear product- fckeditor2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
fckeditor fckeditor Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory. CWE-22Jul 5, 2009 | CVSS7.5v2.0 | EPSS83.9% | PoCs10 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
FCKeditor before 2.3 Beta editor/filemanager/upload/php/upload.php Arbitrary File Uploadeditor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658. May 22, 2006 | CVSS5.0v2.0 | EPSS2.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |