7.5
CVSSv2

CVE-2008-6178

Published: 19/02/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote malicious users to execute arbitrary code by creating a file with PHP sequences preceded by a ZIP header, uploading this file via a FileUpload action with the application/zip content type, and then accessing this file via a direct request to the file in UserFiles/File/, probably a related issue to CVE-2005-4094. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

phplist phplist 2.10.1

fckeditor fckeditor 2.4.3

phplist phplist 2.10.5

phplist phplist 2.10.4

fckeditor fckeditor 2.3beta

fckeditor fckeditor 2.0rc2

fckeditor fckeditor 2.0rc3

fckeditor fckeditor 2.2

phplist phplist 2.10.3

phplist phplist 2.10.2

phplist phplist 2.10.6

Exploits

<?php /* --------------------------------------------------------------- Nuke ET <= 34 (fckeditor) Remote Arbitrary File Upload Exploit --------------------------------------------------------------- author: EgiX mail: n0b0d13s[at]gmail[dot]com link: wwwtruzoneorg/ This PoC was written for educational purp ...
################################################################ # # Falt4 CMS (fckeditor) Arbitrary File Upload Exploit # # Bug Discovered By : Sp3shial # # Sp3shial@ymailcom # # Persian Boys Hacking Team From A Land With A History-Long Background # # Download CMS : downloadssourceforgenet/falt4/falt4extremezip?modtime=1196845455&bi ...