CVE-2009-2324: XSS
Published Jul 5, 2009
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka samples) directory.
Affected Software
27 affected components
FCKeditor FCKeditor<=2.6.4
FCKeditor FCKeditor=2.0
FCKeditor FCKeditor=2.0_fc
FCKeditor FCKeditor=2.0_rc2
FCKeditor FCKeditor=2.0rc2
FCKeditor FCKeditor=2.0rc3
FCKeditor FCKeditor=2.1
FCKeditor FCKeditor=2.1.1
FCKeditor FCKeditor=2.2
FCKeditor FCKeditor=2.3
FCKeditor FCKeditor=2.3-beta
FCKeditor FCKeditor=2.3.1
FCKeditor FCKeditor=2.3.2
FCKeditor FCKeditor=2.3.3
FCKeditor FCKeditor=2.4
FCKeditor FCKeditor=2.4.1
FCKeditor FCKeditor=2.4.2
FCKeditor FCKeditor=2.4.3
FCKeditor FCKeditor=2.5
FCKeditor FCKeditor=2.5-beta
FCKeditor FCKeditor=2.5.1
FCKeditor FCKeditor=2.6
FCKeditor FCKeditor=2.6.1
FCKeditor FCKeditor=2.6.2
FCKeditor FCKeditor=2.6.3
FCKeditor FCKeditor=2.6.3-beta
FCKeditor FCKeditor=2.6.4-beta
Remediation
Patch Available
Event History
Jul 5, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2324?
CVE-2009-2324 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2009-2324?
To fix CVE-2009-2324, upgrade FCKeditor to version 2.6.4.1 or later.
3
What type of attacks can CVE-2009-2324 enable?
CVE-2009-2324 can enable remote attackers to inject arbitrary web scripts or HTML into affected systems.
4
Which versions of FCKeditor are affected by CVE-2009-2324?
CVE-2009-2324 affects FCKeditor versions up to and including 2.6.4.
5
Is there a specific directory vulnerable in CVE-2009-2324?
Yes, the vulnerability is specifically due to components in the samples directory (aka _samples) of FCKeditor.