CVE-2006-0658

FCKeditor 2.0-2.2 - Unauthenticated Arbitrary File Upload via Extension Blacklist Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2006-0658. PoCs published by BlackHawk, rgod.

AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in InoutMailingListManager <= 3.1 to upload a malicious PHP file, which then executes arbitrary commands on the target system. It also retrieves database credentials from the application's configuration file.

Description

Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.

Exploits (2)

exploitdb WORKING POC VERIFIED
by BlackHawk · phpwebappsphp
https://www.exploit-db.com/exploits/3702

This exploit leverages an authentication bypass vulnerability in InoutMailingListManager <= 3.1 to upload a malicious PHP file, which then executes arbitrary commands on the target system. It also retrieves database credentials from the application's configuration file.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: InoutMailingListManager <= 3.1
No auth needed
Prerequisites: Target must have InoutMailingListManager <= 3.1 installed · PHP file upload functionality must be accessible
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1484

This exploit targets FCKEditor versions 2.0 to 2.2, allowing arbitrary file uploads via the PHP connector. It leverages misconfigurations in the `Config[DeniedExtensions][File]` array to upload a malicious shell, enabling remote command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: FCKEditor 2.0 <= 2.2
No auth needed
Prerequisites: PHP connector enabled in config.php · Misconfigured `Config[DeniedExtensions][File]` array · Direct access to the connector.php file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0502
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/424708
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18767
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3702

Scores

EPSS 0.0674
EPSS Percentile 93.1%

Details

Status published
Products (2)
fckeditor/fckeditor 2.0
fckeditor/fckeditor 2.2
Published Feb 13, 2006
Tracked Since Feb 18, 2026