CVE-2006-2529: Medium severity FCKeditor FCKeditor vulnerability
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2529?
CVE-2006-2529 is considered to be a critical vulnerability due to its potential to allow remote file uploads.
How do I fix CVE-2006-2529?
To fix CVE-2006-2529, update FCKeditor to version 2.3 Beta or later, where the Type parameter is properly validated.
What systems are affected by CVE-2006-2529?
CVE-2006-2529 specifically affects FCKeditor versions prior to 2.3 Beta, including version 2.2.
What are the risks associated with CVE-2006-2529?
The risks associated with CVE-2006-2529 include the potential for unauthorized access to the server and execution of arbitrary code.
Can CVE-2006-2529 lead to a remote code execution?
Yes, CVE-2006-2529 can potentially lead to remote code execution if an attacker exploits the vulnerability to upload malicious files.