First published: Mon May 22 2006(Updated: )
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ht Editor | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2529 is considered to be a critical vulnerability due to its potential to allow remote file uploads.
To fix CVE-2006-2529, update FCKeditor to version 2.3 Beta or later, where the Type parameter is properly validated.
CVE-2006-2529 specifically affects FCKeditor versions prior to 2.3 Beta, including version 2.2.
The risks associated with CVE-2006-2529 include the potential for unauthorized access to the server and execution of arbitrary code.
Yes, CVE-2006-2529 can potentially lead to remote code execution if an attacker exploits the vulnerability to upload malicious files.