|
|||
Rule General Information |
---|
Release Date: | 2025-03-04 | |
Rule Name: | FCKeditor connector.php Arbitrary File Upload Vulnerability (CVE-2008-6178) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote attackers to execute arbitrary code by creating a file with PHP sequences preceded by a ZIP header, uploading this file via a FileUpload action with the application/zip content type, and then accessing this file via a direct request to the file in UserFiles/File/, probably a related issue to CVE-2005-4094.NOTE: some of these details are obtained from third party information. | |
Impact: | Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks. | |
Affected OS: | Windows, Linux, Others | |
Reference: | SecurityFocusBID:31812 ExploitDB:8060 http://secunia.com/advisories/33973 http://www.vupen.com/english/advisories/2009/0447 |
|
Solutions |
---|
Please refer to announcements or patches release by the vendor: http://www.fckeditor.net/ |