CVE-2006-0658
FCKEditor 2.0 < 2.2 - 'FileManager connector.php' Arbitrary File Upload
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
4
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2006-02-09 First Exploit
- 2006-02-13 CVE Reserved
- 2006-02-13 CVE Published
- 2023-05-20 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (6)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/1484 | 2006-02-09 | |
https://www.exploit-db.com/exploits/3702 | 2024-08-07 | |
http://retrogod.altervista.org/fckeditor_22_xpl.html | 2024-08-07 | |
http://www.securityfocus.com/archive/1/424708 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/18767 | 2017-10-11 | |
http://www.vupen.com/english/advisories/2006/0502 | 2017-10-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fckeditor Search vendor "Fckeditor" | Fckeditor Search vendor "Fckeditor" for product "Fckeditor" | 2.0 Search vendor "Fckeditor" for product "Fckeditor" and version "2.0" | - |
Affected
| ||||||
Fckeditor Search vendor "Fckeditor" | Fckeditor Search vendor "Fckeditor" for product "Fckeditor" | 2.2 Search vendor "Fckeditor" for product "Fckeditor" and version "2.2" | - |
Affected
|