CVE-2009-2265
Last modified
CVE-2009-2265 is a vulnerability of currently unknown severity. Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.. EPSS estimates a 83.86% chance of exploitation in the next 30 days.
Description
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Fckeditor | Fckeditor | <= 2.6.4 | — |
| Fckeditor | Fckeditor | 2.0 | — |
| Fckeditor | Fckeditor | 2.0_fc | — |
| Fckeditor | Fckeditor | 2.0_rc2 | — |
| Fckeditor | Fckeditor | 2.0rc2 | — |
| Fckeditor | Fckeditor | 2.0rc3 | — |
| Fckeditor | Fckeditor | 2.1 | — |
| Fckeditor | Fckeditor | 2.1.1 | — |
| Fckeditor | Fckeditor | 2.2 | — |
| Fckeditor | Fckeditor | 2.3 | — |
| Fckeditor | Fckeditor | 2.3.1 | — |
| Fckeditor | Fckeditor | 2.3.2 | — |
| Fckeditor | Fckeditor | 2.3.3 | — |
| Fckeditor | Fckeditor | 2.4 | — |
| Fckeditor | Fckeditor | 2.4.1 | — |
| Fckeditor | Fckeditor | 2.4.2 | — |
| Fckeditor | Fckeditor | 2.4.3 | — |
| Fckeditor | Fckeditor | 2.5 | — |
| Fckeditor | Fckeditor | 2.5.1 | — |
| Fckeditor | Fckeditor | 2.6 | — |
| Fckeditor | Fckeditor | 2.6.1 | — |
| Fckeditor | Fckeditor | 2.6.2 | — |
| Fckeditor | Fckeditor | 2.6.3 | — |
| Fckeditor | Fckeditor | 2.6.4 | Beta |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2265?
How severe is CVE-2009-2265?
How do I fix CVE-2009-2265?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-2258Directory traversal vulnerability in cgi-bin/webcm in the ad…
- CVE-2009-2259Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2009-2260stardict 3.0.1, when Enable Net Dict is configured, sends th…
- CVE-2009-2261PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assi…
- CVE-2009-2262PHP remote file inclusion vulnerability in install/di.php in…
- CVE-2009-2263Directory traversal vulnerability in index.php in Awesome PH…
- CVE-2009-2266OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remot…
- CVE-2009-2267VMware Workstation 6.5.x before 6.5.3 build 185404, VMware P…
- CVE-2009-2268Cross-site scripting (XSS) vulnerability in the Cross-Domain…
- CVE-2009-2269SQL injection vulnerability in Empire CMS 5.1 allows remote …
- CVE-2009-2270Unrestricted file upload vulnerability in member/uploads_edi…
- CVE-2009-2271The Huawei D100 has (1) a certain default administrator pass…
Are you affected by CVE-2009-2265?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
