5
CVSSv2

CVE-2006-2529

Published: 22/05/2006 Updated: 08/03/2011
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

editor/filemanager/upload/php/upload.php in FCKeditor prior to 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote malicious users to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658.

Vulnerable Product Search on Vulmon Subscribe to Product

fckeditor fckeditor 2.2

Vendor Advisories

Debian Bug report logs - #444928 CVE-2007-5156 remote php file inclusion vulnerability in fckeditor Package: knowledgeroot; Maintainer for knowledgeroot is (unknown); Reported by: Nico Golde <nion@debianorg> Date: Mon, 1 Oct 2007 22:39:01 UTC Severity: grave Tags: patch, security Fixed in versions knowledgeroot/0984- ...