CVE-2009-2265: Path Traversal
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2009-2265?
CVE-2009-2265 allows remote attackers to create executable files in arbitrary directories, leading to potential remote code execution.
What versions of FCKeditor are affected by CVE-2009-2265?
CVE-2009-2265 affects multiple versions of FCKeditor prior to 2.6.4.1, including versions 2.4 to 2.6.4.
How can I fix CVE-2009-2265?
To fix CVE-2009-2265, upgrade FCKeditor to version 2.6.4.1 or later.
How does CVE-2009-2265 exploit directory traversal vulnerabilities?
CVE-2009-2265 exploits directory traversal vulnerabilities by using special character sequences in user inputs to access unauthorized directories.
Is CVE-2009-2265 still a relevant threat today?
While CVE-2009-2265 is an older vulnerability, it remains relevant for legacy systems still using vulnerable versions of FCKeditor.