PT-2007-4446 · Freddie Chung · Ckeditor

Published

2007-06-11

·

Updated

2024-02-14

·

CVE-2007-3163

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: FCKeditor version 2.4.2
Description: The issue is related to an incomplete blacklist vulnerability in the filemanager component. This allows remote attackers to upload arbitrary .php files using an alternate data stream syntax, such as .php::$DATA filenames.
Recommendations: For version 2.4.2, consider restricting the upload of .php files to prevent exploitation until a patch is available. As a temporary workaround, restrict access to the filemanager component to minimize the risk of uploading malicious files.

Fix

Related Identifiers

CVE-2007-3163

Affected Products

Ckeditor