CVE-2009-2265

EXPLOITED IN THE WILD

FCKeditor <2.6.4.1 - Path Traversal

Title source: llm

Description

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

Exploits (10)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappscfm
https://www.exploit-db.com/exploits/16788
exploitdb WORKING POC
by Pergyz · pythonwebappscfm
https://www.exploit-db.com/exploits/50057
nomisec WORKING POC 2 stars
by zaphoxx · poc
https://github.com/zaphoxx/zaphoxx-coldfusion
nomisec WORKING POC 1 stars
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2009-2265
nomisec WORKING POC 1 stars
by 0xDTC · remote
https://github.com/0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265
nomisec WORKING POC 1 stars
by p1ckzi · client-side
https://github.com/p1ckzi/CVE-2009-2265
nomisec WORKING POC
by matesz44 · remote
https://github.com/matesz44/CVE-2009-2265
nomisec WORKING POC
by nika0x38 · remote
https://github.com/nika0x38/CVE-2009-2265
github WORKING POC
by dugisan3rd · pythonpoc
https://github.com/dugisan3rd/exploit/tree/main/cve-2009-2265
metasploit WORKING POC EXCELLENT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/coldfusion_fckeditor.rb

Scores

EPSS 0.9276
EPSS Percentile 99.8%

Details

VulnCheck KEV 2009-07-05
InTheWild.io 2021-06-24
CWE
CWE-22
Status published
Products (24)
fckeditor/fckeditor 2.0
fckeditor/fckeditor 2.0_fc
fckeditor/fckeditor 2.0_rc2
fckeditor/fckeditor 2.0rc2
fckeditor/fckeditor 2.0rc3
fckeditor/fckeditor 2.1
fckeditor/fckeditor 2.1.1
fckeditor/fckeditor 2.2
fckeditor/fckeditor 2.3 (2 CPE variants)
fckeditor/fckeditor 2.3.1
... and 14 more
Published Jul 05, 2009
Tracked Since Feb 18, 2026