Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.
📦
fckeditor
Vendor: fckeditor
Actively Exploited
0
CISA KEV List
PoC / Exploits
5
Code Available
Total RCEs
1
Remote Access
Total CVEs
15
Total Indexed
Avg. EPSS
9.32%
Exploit Prob.
Security Vulnerability Index
Page 2 / 2
6.4
CVSS
Severity: MEDIUM
5.0
CVSS
CVE-2006-0658
Exploit Found
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
Severity: MEDIUM
5.0
CVSS
CVE-2005-0613
Exploit Found
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
Severity: MEDIUM