PT-2007-4446 · Freddie Chung · Ckeditor
CVE-2007-3163
·
Publicado
2007-06-11
·
Atualizado
2024-02-14
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
FCKeditor version 2.4.2
Description:
The issue is related to an incomplete blacklist vulnerability in the filemanager component. This allows remote attackers to upload arbitrary .php files using an alternate data stream syntax, such as .php::$DATA filenames.
Recommendations:
For version 2.4.2, consider restricting the upload of .php files to prevent exploitation until a patch is available. As a temporary workaround, restrict access to the filemanager component to minimize the risk of uploading malicious files.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ckeditor