vendor:
FCKEditor
by:
rgod
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: FCKEditor
Affected Version From: 2
Affected Version To: 2.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2005
FCKEditor 2.0 <= 2.2 shell upload
This exploit allows an attacker to upload malicious content, including arbitrary PHP code, to a target server through the FCKEditor file manager connector. It relies on the misconfiguration of the PHP connector and the use of an extension not specified in the FCKEditor configuration.
Mitigation:
To mitigate this vulnerability, ensure that the PHP connector in FCKEditor is properly configured and restrict the allowed file extensions.