4.3
CVSSv2

CVE-2009-2324

Published: 05/07/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor prior to 2.6.4.1 allow remote malicious users to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.

Vulnerable Product Search on Vulmon Subscribe to Product

fckeditor fckeditor 2.0_fc

fckeditor fckeditor 2.0_rc2

fckeditor fckeditor 2.0rc2

fckeditor fckeditor 2.0rc3

fckeditor fckeditor 2.2

fckeditor fckeditor 2.6

fckeditor fckeditor 2.5.1

fckeditor fckeditor 2.3.1

fckeditor fckeditor 2.3

fckeditor fckeditor 2.4.3

fckeditor fckeditor 2.4.2

fckeditor fckeditor 2.5

fckeditor fckeditor 2.1.1

fckeditor fckeditor 2.6.2

fckeditor fckeditor 2.6.1

fckeditor fckeditor 2.3.3

fckeditor fckeditor 2.3.2

fckeditor fckeditor 2.6.4

fckeditor fckeditor 2.0

fckeditor fckeditor 2.6.3

fckeditor fckeditor 2.4.1

fckeditor fckeditor 2.4

fckeditor fckeditor 2.1

fckeditor fckeditor

Vendor Advisories

Debian Bug report logs - #536051 CVE-2009-2265, CVE-2009-2324: input sanitization errors Package: fckeditor; Maintainer for fckeditor is (unknown); Reported by: Giuseppe Iuculano <giuseppe@iuculanoit> Date: Tue, 7 Jul 2009 06:45:01 UTC Severity: grave Tags: lenny, security Found in version fckeditor/1:262-1 Fixed in v ...