vendor:
FCKeditor
by:
trycyber
7,5
CVSS
HIGH
File upload vulnerabilities
434
CWE
Product Name: FCKeditor
Affected Version From: 1.62
Affected Version To: 1.62
Patch Exists: NO
Related CWE: N/A
CPE: phpmotion/FCKeditor
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win Xp sp2
2010
phpmotion/FCKeditor File upload vulnerabilities
By default, the vulnerable application can be accessed at http://127.0.0.1/. An attacker can exploit this vulnerability by accessing the URL http://127.0.0.1/phpmotion/fckeditor/editor/filemanager/connectors/test.html, which will allow them to upload a file to the server. The uploaded file can then be accessed at http://127.0.0.1/userfiles/name of file.
Mitigation:
Ensure that the application is configured to only allow the upload of files with the appropriate file extensions and that the application is configured to only allow the upload of files with the appropriate file size.