Lucene search

K
cve[email protected]CVE-2009-2265
HistoryJul 05, 2009 - 4:30 p.m.

CVE-2009-2265

2009-07-0516:30:00
CWE-22
web.nvd.nist.gov
159
1
cve
2009
2265
fckeditor
directory traversal
remote code execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.972 High

EPSS

Percentile

99.8%

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

Affected configurations

NVD
Node
fckeditorfckeditorRangeโ‰ค2.6.4
OR
fckeditorfckeditorMatch2.0
OR
fckeditorfckeditorMatch2.0_fc
OR
fckeditorfckeditorMatch2.0_rc2
OR
fckeditorfckeditorMatch2.0rc2
OR
fckeditorfckeditorMatch2.0rc3
OR
fckeditorfckeditorMatch2.1
OR
fckeditorfckeditorMatch2.1.1
OR
fckeditorfckeditorMatch2.2
OR
fckeditorfckeditorMatch2.3
OR
fckeditorfckeditorMatch2.3beta
OR
fckeditorfckeditorMatch2.3.1
OR
fckeditorfckeditorMatch2.3.2
OR
fckeditorfckeditorMatch2.3.3
OR
fckeditorfckeditorMatch2.4
OR
fckeditorfckeditorMatch2.4.1
OR
fckeditorfckeditorMatch2.4.2
OR
fckeditorfckeditorMatch2.4.3
OR
fckeditorfckeditorMatch2.5
OR
fckeditorfckeditorMatch2.5beta
OR
fckeditorfckeditorMatch2.5.1
OR
fckeditorfckeditorMatch2.6
OR
fckeditorfckeditorMatch2.6.1
OR
fckeditorfckeditorMatch2.6.2
OR
fckeditorfckeditorMatch2.6.3
OR
fckeditorfckeditorMatch2.6.3beta
OR
fckeditorfckeditorMatch2.6.4beta

Social References

More

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.972 High

EPSS

Percentile

99.8%