PT-2007-4446 · Freddie Chung · Ckeditor
Published
2007-06-11
·
Updated
2024-02-14
·
CVE-2007-3163
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
FCKeditor version 2.4.2
Description:
The issue is related to an incomplete blacklist vulnerability in the filemanager component. This allows remote attackers to upload arbitrary .php files using an alternate data stream syntax, such as .php::$DATA filenames.
Recommendations:
For version 2.4.2, consider restricting the upload of .php files to prevent exploitation until a patch is available. As a temporary workaround, restrict access to the filemanager component to minimize the risk of uploading malicious files.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ckeditor