First published: Sun Jul 05 2009(Updated: )
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ht Editor | =2.4 | |
Ht Editor | =2.6.3-beta | |
Ht Editor | =2.6.3 | |
Ht Editor | <=2.6.4 | |
Ht Editor | =2.6 | |
Ht Editor | =2.4.3 | |
Ht Editor | =2.5 | |
Ht Editor | =2.3-beta | |
Ht Editor | =2.3.3 | |
Ht Editor | =2.5-beta | |
Ht Editor | =2.4.2 | |
Ht Editor | =2.4.1 | |
Ht Editor | =2.1 | |
Ht Editor | =2.0rc3 | |
Ht Editor | =2.0_fc | |
Ht Editor | =2.6.2 | |
Ht Editor | =2.3.1 | |
Ht Editor | =2.0 | |
Ht Editor | =2.2 | |
Ht Editor | =2.5.1 | |
Ht Editor | =2.0rc2 | |
Ht Editor | =2.0_rc2 | |
Ht Editor | =2.1.1 | |
Ht Editor | =2.3 | |
Ht Editor | =2.6.1 | |
Ht Editor | =2.6.4-beta | |
Ht Editor | =2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2265 allows remote attackers to create executable files in arbitrary directories, leading to potential remote code execution.
CVE-2009-2265 affects multiple versions of FCKeditor prior to 2.6.4.1, including versions 2.4 to 2.6.4.
To fix CVE-2009-2265, upgrade FCKeditor to version 2.6.4.1 or later.
CVE-2009-2265 exploits directory traversal vulnerabilities by using special character sequences in user inputs to access unauthorized directories.
While CVE-2009-2265 is an older vulnerability, it remains relevant for legacy systems still using vulnerable versions of FCKeditor.