1
Rhomal
FCKeditor File Upload Vulnerability
  • 2006/2/10 15:06

  • Rhomal

  • Quite a regular

  • Posts: 274

  • Since: 2004/10/5


Secunia Advisory: SA18767 Print Advisory
Release Date: 2006-02-10

Critical:
Moderately critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software: FCKeditor 2.x

Select a product and view a complete list of all Patched/Unpatched Secunia advisories affecting it.

Description:
rgod has discovered a vulnerability in FCKeditor, which potentially can be exploited by malicious people to compromise a vulnerable system.

The problem is that it is possible to upload arbitrary files to a location inside the web root if the file extension does not match the list of denied file extensions. This can e.g. be exploited to upload and execute a malicious PHP script with the ".php.txt" file extension.

Successful exploitation requires that file uploads have been enabled in the "config.php" configuration file (not enabled by default).

The vulnerability has been confirmed in version 2.2 and has also been reported in version 2.0. Other versions may also be affected.

Solution:
Disable file uploads in "config.php".

Source:
http://secunia.com/advisories/18767/

Login

Who's Online

170 user(s) are online (152 user(s) are browsing Support Forums)


Members: 0


Guests: 170


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Apr 30
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits