5
CVSSv2

CVE-2006-0658

Published: 13/02/2006 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote malicious users to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.

Vulnerable Product Search on Vulmon Subscribe to Product

fckeditor fckeditor 2.0

fckeditor fckeditor 2.2

Vendor Advisories

Debian Bug report logs - #444928 CVE-2007-5156 remote php file inclusion vulnerability in fckeditor Package: knowledgeroot; Maintainer for knowledgeroot is (unknown); Reported by: Nico Golde <nion@debianorg> Date: Mon, 1 Oct 2007 22:39:01 UTC Severity: grave Tags: patch, security Fixed in versions knowledgeroot/0984- ...

Exploits

<?php # ---fckeditor_22_xplphp 1538 04/12/2005 # # # # FCKEditor 20 <= 22 shell upload # # coded by rgod # # ...
#!/usr/bin/php -q -d short_open_tag=on <? echo " InoutMailingListManager <= 31 Command Execution Exploit + Login Retrieve + Advisory by BlackHawk <hawkgotyou@gmailcom> <itablackhawkaltervistaorg> Thanks to rgod for the php code and Marty for the Love "; if ($argc<4) { echo "Usage: php "$argv[0]" Site CMD Host: ...