CVE-2006-0658
Last modified
CVE-2006-0658 is a vulnerability of currently unknown severity. Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.. EPSS estimates a 6.74% chance of exploitation in the next 30 days.
Description
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fckeditor | Fckeditor | 2.0 |
| Fckeditor | Fckeditor | 2.2 |
References
- http://secunia.com/advisories/18767Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0502Vendor Advisory
- http://secunia.com/advisories/18767Vendor Advisory
- http://www.vupen.com/english/advisories/2006/0502Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0658?
How severe is CVE-2006-0658?
How do I fix CVE-2006-0658?
Are you affected by CVE-2006-0658?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
