First published: Wed May 26 2010(Updated: )
FCKeditor.Java 2.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed request parameter that contains "ctrl" characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CKEditor | =2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4875 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2009-4875, consider updating FCKeditor.Java to a version where this vulnerability is addressed or implement input validation to sanitize request parameters.
CVE-2009-4875 can be exploited via crafted requests containing "ctrl" characters, leading to an infinite loop and denial of service.
CVE-2009-4875 specifically affects FCKeditor.Java version 2.4.
While CVE-2009-4875 was reported in 2009, it remains a threat for systems that have not been updated or secured against this specific vulnerability.