vendor:
CMS (fckeditor)
by:
Sp3shial
7.5
CVSS
HIGH
Arbitrary File Upload
264
CWE
Product Name: CMS (fckeditor)
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Falt4 CMS (fckeditor) Arbitrary File Upload Exploit
This exploit allows an attacker to upload a malicious file to the vulnerable server. The malicious file contains a payload which allows the attacker to execute arbitrary commands on the server. The vulnerability exists due to insufficient validation of the uploaded file. The exploit was discovered by Sp3shial and was published in 2008.
Mitigation:
The best way to mitigate this vulnerability is to ensure that all uploaded files are properly validated before being stored on the server.