Record summary

CVE-2006-2529 has a selected CVSS score of 5.0.

Description

editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 28, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

References

6