PT-2007-3949 · Fredck+1 · Ckeditor+1

Publicado

2007-05-11

·

Atualizado

2018-10-16

·

CVE-2007-2630

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ActiveCampaign 1-2-All (aka 12All) versions 4.50 through 4.53.13
Description The issue is related to an incomplete blacklist vulnerability in the FCKeditor module, specifically in the filemanager/browser/default/connectors/php/config.php file. This allows remote authenticated administrators to upload and possibly execute .php4 and .php5 files. The vulnerability can be reached through the filemanager/browser/default/browser.html file.
Recommendations For ActiveCampaign 1-2-All (aka 12All) versions 4.50 through 4.53.13, consider restricting access to the filemanager/browser/default/connectors/php/config.php file and the filemanager/browser/default/browser.html file to prevent potential exploitation. As a temporary workaround, consider disabling the upload functionality for .php4 and .php5 files in the FCKeditor module until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2630

Produtos afetados

Activecampaign
Ckeditor