CVE-2006-3362

FCKeditor mcpuk - Unrestricted File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2006-3362. PoCs published by Stack, rgod.

AI-analyzed exploit summary This exploit targets a file upload vulnerability in WeBid v0.5.4's FCKeditor component, allowing arbitrary PHP file upload by bypassing extension checks. It uploads a malicious PHP shell disguised with allowed extensions (e.g., .swf, .doc) and provides interactive command execution.

Description

Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Stack · phpwebappsphp
https://www.exploit-db.com/exploits/6344

This exploit targets a file upload vulnerability in WeBid v0.5.4's FCKeditor component, allowing arbitrary PHP file upload by bypassing extension checks. It uploads a malicious PHP shell disguised with allowed extensions (e.g., .swf, .doc) and provides interactive command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WeBid v0.5.4 (FCKeditor)
No auth needed
Prerequisites: Network access to the target · FCKeditor component enabled in WeBid
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/2035

This exploit targets ToendaCMS <= 1.0.0 by uploading a malicious PHP file disguised as an allowed file type via the FCKeditor file upload functionality. It then executes arbitrary commands by sending a crafted GET request with the command embedded in a cookie.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ToendaCMS <= 1.0.0
No auth needed
Prerequisites: Target must have ToendaCMS <= 1.0.0 installed · FCKeditor file upload functionality must be accessible · Network access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1964

This exploit targets Geeklog <= 1.4.0sr3 by uploading a malicious PHP file via the unprotected FCKeditor connector. It achieves remote command execution by leveraging a file upload vulnerability in the 'mcpuk' connector.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Geeklog <= 1.4.0sr3
No auth needed
Prerequisites: FCKeditor enabled with unprotected connector.php · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (17)

Core 17
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19072
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18767
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30950
Various Sources x_refsource_confirm
http://www.geeklog.net/article.php/geeklog-1.4.0sr4
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27469
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27799
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2868
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6344
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2035
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1964
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20886
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27494
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/440423/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21117
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2611

Scores

EPSS 0.0497
EPSS Percentile 91.1%

Details

Status published
Products (8)
geeklog/geeklog 1.4.0
geeklog/geeklog 1.4.0_sr1
geeklog/geeklog 1.4.0_sr2
geeklog/geeklog 1.4.0_sr3
toenda_software_development/toendacms 0.6.1
toenda_software_development/toendacms 0.6.2
toenda_software_development/toendacms 0.7
toenda_software_development/toendacms 1.0
Published Jul 06, 2006
Tracked Since Feb 18, 2026