PT-2007-4446 · Freddie Chung · Ckeditor

CVE-2007-3163

·

Publicado

2007-06-11

·

Atualizado

2024-02-14

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: FCKeditor version 2.4.2
Description: The issue is related to an incomplete blacklist vulnerability in the filemanager component. This allows remote attackers to upload arbitrary .php files using an alternate data stream syntax, such as .php::$DATA filenames.
Recommendations: For version 2.4.2, consider restricting the upload of .php files to prevent exploitation until a patch is available. As a temporary workaround, restrict access to the filemanager component to minimize the risk of uploading malicious files.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3163

Produtos afetados

Ckeditor