CVE-2009-2265
- EPSS 93.05%
- Veröffentlicht 05.07.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the w...
CVE-2009-2324
- EPSS 0.25%
- Veröffentlicht 05.07.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.
CVE-2008-6178
- EPSS 9.47%
- Veröffentlicht 19.02.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4 CMS, Nuke ET, and other products, allows remote attackers to execute arbitrary code by creating a file with P...
CVE-2006-6978
- EPSS 0.45%
- Veröffentlicht 08.02.2007 17:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag.
- EPSS 0.73%
- Veröffentlicht 22.05.2006 23:10:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is relate...
CVE-2006-0921
- EPSS 0.28%
- Veröffentlicht 28.02.2006 11:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFolders...
- EPSS 5.68%
- Veröffentlicht 13.02.2006 11:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the ...
- EPSS 2.79%
- Veröffentlicht 28.02.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.