Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:28879
HistoryDec 18, 2012 - 12:00 a.m.

FCKEditor File Upload Vulnerability

2012-12-1800:00:00
vulners.com
123
  • Description:
    There is no validation on the extensions when FCKEditor 2.6.8 ASP version is
    dealing with the duplicate files. As a result, it is possible to bypass
    the protection and upload a file with any extension.

  • Reference: http://www.exploit-db.com/exploits/23005/

vulnerable versions: prior to 2.6.9

Vendor Response: http://ckeditor.com/forums/Announcements/FCKeditor-2.6.9-Released