CVE-2006-3362
FCKeditor mcpuk - Unrestricted File Upload
Title source: llmDescription
Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.
Exploits (3)
References (17)
Scores
EPSS
0.1521
EPSS Percentile
94.5%
Classification
Status
draft
Affected Products (8)
geeklog/geeklog
geeklog/geeklog
geeklog/geeklog
geeklog/geeklog
toenda_software_development/toendacms
toenda_software_development/toendacms
toenda_software_development/toendacms
toenda_software_development/toendacms
Timeline
Published
Jul 06, 2006
Tracked Since
Feb 18, 2026