CVE-2006-0658 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 6.9% (pctl 94)
Patch early
A public exploit exists.
Description
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
| EPSS | 6.9% — more likely to be exploited than 94% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-02-13 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| fckeditor | fckeditor |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | InoutMailingListManager 3.1 - Remote Command Execution | 2007-04-10 |
| exploit-db | FCKEditor 2.0 < 2.2 - 'FileManager connector.php' Arbitrary File Upload | 2006-02-09 |
References
- http://retrogod.altervista.org/fckeditor_22_xpl.html
- http://secunia.com/advisories/18767
- http://www.securityfocus.com/archive/1/424708
- http://www.vupen.com/english/advisories/2006/0502
- https://www.exploit-db.com/exploits/3702
- http://retrogod.altervista.org/fckeditor_22_xpl.html
- http://secunia.com/advisories/18767
- http://www.securityfocus.com/archive/1/424708
- http://www.vupen.com/english/advisories/2006/0502
- https://www.exploit-db.com/exploits/3702
→ the Explorer · watch your stack · NVD