PT-2005-4826 · Fredck+1 · Ckeditor+1

Publicado

2005-12-08

·

Atualizado

2017-07-20

·

CVE-2005-4094

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DoceboLMS version 2.0.4
Description The issue allows remote attackers to execute arbitrary PHP code by uploading a file that appears to be an image but contains PHP script using the FileUpload command in the connector.php file of the fckeditor2rc2 addon.
Recommendations For DoceboLMS version 2.0.4, consider disabling the FileUpload command in the connector.php file of the fckeditor2rc2 addon until a patch is available. Restrict access to the connector.php file to minimize the risk of exploitation. Avoid using the FileUpload command to upload files that could potentially contain PHP script.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4094

Produtos afetados

Docebolms
Ckeditor