First published: Mon Feb 13 2006(Updated: )
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ht Editor | =2.0 | |
Ht Editor | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0658 is considered a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2006-0658, ensure that the DeniedExtensions configuration in FCKeditor includes all potential script file extensions.
FCKeditor versions 2.0 and 2.2 are affected by CVE-2006-0658.
CVE-2006-0658 represents an incomplete blacklist vulnerability allowing unauthorized file uploads.
Yes, CVE-2006-0658 can lead to data breaches if attackers upload and execute malicious scripts.