CVE-2009-2265
EXPLOITED IN THE WILDFCKeditor <2.6.4.1 - Path Traversal
Title source: llmDescription
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.
Exploits (10)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappscfm
https://www.exploit-db.com/exploits/16788
nomisec
WORKING POC
1 stars
by 0xDTC · remote
https://github.com/0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265
github
WORKING POC
by dugisan3rd · pythonpoc
https://github.com/dugisan3rd/exploit/tree/main/cve-2009-2265
metasploit
WORKING POC
EXCELLENT
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/coldfusion_fckeditor.rb
References (14)
Scores
EPSS
0.9276
EPSS Percentile
99.8%
Details
VulnCheck KEV
2009-07-05
InTheWild.io
2021-06-24
CWE
CWE-22
Status
published
Products (24)
fckeditor/fckeditor
2.0
fckeditor/fckeditor
2.0_fc
fckeditor/fckeditor
2.0_rc2
fckeditor/fckeditor
2.0rc2
fckeditor/fckeditor
2.0rc3
fckeditor/fckeditor
2.1
fckeditor/fckeditor
2.1.1
fckeditor/fckeditor
2.2
fckeditor/fckeditor
2.3 (2 CPE variants)
fckeditor/fckeditor
2.3.1
... and 14 more
Published
Jul 05, 2009
Tracked Since
Feb 18, 2026