peter bassill · operator
$ cve CVE-2006-3362 JSON

CVE-2006-3362 EXPLOIT

5.1
MEDIUM · CVSS 2.0 · EPSS 5.1% (pctl 92)

Patch early

A public exploit exists.

Description

Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka Stable and earlier, (3) WeBid 0.5.4, and possibly other products, when installed on Apache with mod_mime, allows remote attackers to upload and execute arbitrary PHP code via a filename with a .php extension and a trailing extension that is allowed, such as .zip.

Scoring

CVSS5.1 (MEDIUM, v2.0)
VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
EPSS5.06% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2006-07-06
Last modified2026-06-16

Affected (2)

VendorProduct
geekloggeeklog
toenda software developmenttoendacms

Public exploits

SourceTitleDate
exploit-dbGeekLog 1.4.0sr3 - 'f(u)ckeditor' Remote Code Execution2006-06-29

References

→ the Explorer  ·  watch your stack  ·  NVD