peter bassill · operator
$ cve CVE-2006-0658 JSON

CVE-2006-0658 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 6.9% (pctl 94)

Patch early

A public exploit exists.

Description

Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS6.9% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2006-02-13
Last modified2026-06-16

Affected (1)

VendorProduct
fckeditorfckeditor

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD