Vulnerabilities > CVE-2006-0658 - Remote Security vulnerability in Fckeditor 2.0/2.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt. Per: http://cwe.mitre.org/data/definitions/184.html 'CWE-184: Incomplete Blacklist'
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description FCKEditor 2.0. CVE-2006-0658. Webapps exploit for php platform id EDB-ID:1484 last seen 2016-01-31 modified 2006-02-09 published 2006-02-09 reporter rgod source https://www.exploit-db.com/download/1484/ title FCKEditor 2.0 <= 2.2 - FileManager - connector.php Remote Shell Upload Exploit description InoutMailingListManager <= 3.1 Remote Command Execution Exploit. CVE-2005-0613,CVE-2006-0658,CVE-2007-2002,CVE-2007-2003,CVE-2007-2004. Webapps exploit fo... file exploits/php/webapps/3702.php id EDB-ID:3702 last seen 2016-01-31 modified 2007-04-10 platform php port published 2007-04-10 reporter BlackHawk source https://www.exploit-db.com/download/3702/ title InoutMailingListManager <= 3.1 - Remote Command Execution Exploit type webapps