First published: Sun Jul 05 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ht Editor | =2.4 | |
Ht Editor | =2.6.3-beta | |
Ht Editor | =2.6.3 | |
Ht Editor | <=2.6.4 | |
Ht Editor | =2.6 | |
Ht Editor | =2.4.3 | |
Ht Editor | =2.5 | |
Ht Editor | =2.3-beta | |
Ht Editor | =2.3.3 | |
Ht Editor | =2.5-beta | |
Ht Editor | =2.4.2 | |
Ht Editor | =2.4.1 | |
Ht Editor | =2.1 | |
Ht Editor | =2.0rc3 | |
Ht Editor | =2.0_fc | |
Ht Editor | =2.6.2 | |
Ht Editor | =2.3.1 | |
Ht Editor | =2.0 | |
Ht Editor | =2.2 | |
Ht Editor | =2.5.1 | |
Ht Editor | =2.0rc2 | |
Ht Editor | =2.0_rc2 | |
Ht Editor | =2.1.1 | |
Ht Editor | =2.3 | |
Ht Editor | =2.6.1 | |
Ht Editor | =2.6.4-beta | |
Ht Editor | =2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2324 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2009-2324, upgrade FCKeditor to version 2.6.4.1 or later.
CVE-2009-2324 can enable remote attackers to inject arbitrary web scripts or HTML into affected systems.
CVE-2009-2324 affects FCKeditor versions up to and including 2.6.4.
Yes, the vulnerability is specifically due to components in the samples directory (aka _samples) of FCKeditor.