This exploit demonstrates a Full Path Disclosure (FPD) and Cross-Site Scripting (XSS) vulnerability in CKEditor 4.0.1. The FPD occurs due to improper handling of array inputs in the `posteddata.php` script, while the XSS is achievable via crafted POST data.
Classification
Working Poc 95%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target:CKEditor 4.0.1 standard
No auth needed
Prerequisites:Access to the vulnerable `posteddata.php` endpoint · Ability to send crafted POST requests