20122Third-party advisory
http://secunia.com/advisories/20122 CVE-2006-2529
FCKeditor before 2.3 Beta editor/filemanager/upload/php/upload.php Arbitrary File Upload
Record summary
CVE-2006-2529 has a selected CVSS score of 5.0.
Description
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 28, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
fckeditorBrowse fckeditor / fckeditor | VulnCheck | Version data not supplied | |
References
6fckeditor.netConfirmation
http://www.fckeditor.net/whatsnew/default.html 25631vdb entry
http://www.osvdb.org/25631 18029vdb entry
http://www.securityfocus.com/bid/18029 ADV-2006-1856vdb entry
http://www.vupen.com/english/advisories/2006/1856 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-2529