Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-2265

Опубликовано: 05 июл. 2009
Источник: ubuntu
Приоритет: low
EPSS Критический
CVSS2: 7.5

Описание

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

hardy

ignored

end of life
intrepid

released

1:2.6.2-1lenny1build0.8.10.1
jaunty

ignored

end of life
karmic

not-affected

1:2.6.4.1-1
lucid

not-affected

maverick

not-affected

natty

not-affected

oneiric

not-affected

Показывать по

РелизСтатусПримечание
dapper

not-affected

code not present
devel

not-affected

system fckeditor
hardy

not-affected

code not present
intrepid

not-affected

code not present
jaunty

not-affected

system fckeditor
karmic

not-affected

system fckeditor
lucid

not-affected

system fckeditor
maverick

not-affected

system fckeditor
natty

not-affected

system fckeditor
oneiric

not-affected

system fckeditor

Показывать по

Ссылки на источники

EPSS

Процентиль: 100%
0.92328
Критический

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

nvd
больше 16 лет назад

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

debian
больше 16 лет назад

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4 ...

github
почти 4 года назад

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

CVSS3: 6.3
fstec
почти 17 лет назад

Уязвимость WYSIWYG-редактора Ckeditor, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом. позволяющая нарушителю загрузить произвольные файлы

EPSS

Процентиль: 100%
0.92328
Критический

7.5 High

CVSS2