Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-2265

Опубликовано: 05 июл. 2009
Источник: debian
EPSS Критический

Описание

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fckeditorfixed1:2.6.4.1-1package
moinfixed1.8.2-2package
moinunfixedlennypackage
moinnot-affectedetchpackage
request-tracker3.8not-affectedpackage
egroupwarefixed1.6.002+dfsg-1package
egroupwarefixed1.4.004-2.dfsg-4.2lennypackage
gforgefixed4.6.99+svn6225-1package
gforgenot-affectedetchpackage
knowledgerootfixed0.9.8.5-3package
karrigellremovedpackage
karrigellnot-affectedetchpackage

Примечания

  • http://dev.fckeditor.net/changeset/3815/FCKeditor/trunk/editor/filemanager

  • moin from 1.8.2-2 uses systemwide copy of fckeditor

  • moin in lenny provides FCKeditor as example files (/usr/share/doc)

  • knowledgeroot from 0.9.8.5-3 uses systemwide copy of fckeditor

EPSS

Процентиль: 100%
0.90873
Критический

Связанные уязвимости

ubuntu
больше 16 лет назад

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

redhat
больше 16 лет назад

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

nvd
больше 16 лет назад

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

github
почти 4 года назад

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

CVSS3: 6.3
fstec
почти 17 лет назад

Уязвимость WYSIWYG-редактора Ckeditor, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом. позволяющая нарушителю загрузить произвольные файлы

EPSS

Процентиль: 100%
0.90873
Критический