fckeditor records
8 published records for vendor fckeditor.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 12.5%
- Pre-auth RCE
- 4
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2009-2265Weaponized | Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary direfckeditor · fckeditor · CWE-22 | High7.5 | — | 83.7% | Jul 5, 2009 |
32Monitor | CVE-2008-6178Proof of concept | Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4fckeditor · fckeditor · CWE-94 | High7.5 | — | 7.8% | Feb 19, 2009 |
26Monitor | CVE-2006-0921No exploit | Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackerfckeditor · fckeditor | Medium6.4 | — | 1.7% | Feb 28, 2006 |
22Monitor | CVE-2006-0658Proof of concept | Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers tofckeditor · fckeditor | Medium5.0 | — | 6.9% | Feb 13, 2006 |
21Monitor | CVE-2005-0613Proof of concept | Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.fckeditor · fckeditor | Medium5.0 | — | 4.6% | Feb 28, 2005 |
21Monitor | CVE-2006-2529No exploit | editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parametefckeditor · fckeditor | Medium5.0 | — | 2.4% | May 22, 2006 |
18Monitor | CVE-2009-2324No exploit | Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTMfckeditor · fckeditor · CWE-79 | Medium4.3 | — | 1.7% | Jul 5, 2009 |
17Monitor | CVE-2006-6978No exploit | Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScrifckeditor · fckeditor · CWE-79 | Medium4.3 | — | 1.1% | Feb 8, 2007 |
- CVE-2009-226555Plan
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary dire
HighCVSS 7.5WeaponizedEPSS 84%fckeditor · fckeditorJul 5, 2009
- CVE-2008-617832Monitor
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2.2, as used in Falt4
HighCVSS 7.5Proof of conceptEPSS 8%fckeditor · fckeditorFeb 19, 2009
- CVE-2006-092126Monitor
Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attacker
MediumCVSS 6.4No exploitEPSS 2%fckeditor · fckeditorFeb 28, 2006
- CVE-2006-065822Monitor
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to
MediumCVSS 5.0Proof of conceptEPSS 7%fckeditor · fckeditorFeb 13, 2006
- CVE-2005-061321Monitor
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
MediumCVSS 5.0Proof of conceptEPSS 5%fckeditor · fckeditorFeb 28, 2005
- CVE-2006-252921Monitor
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type paramete
MediumCVSS 5.0No exploitEPSS 2%fckeditor · fckeditorMay 22, 2006
- CVE-2009-232418Monitor
Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTM
MediumCVSS 4.3No exploitEPSS 2%fckeditor · fckeditorJul 5, 2009
- CVE-2006-697817Monitor
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScri
MediumCVSS 4.3No exploitEPSS 1%fckeditor · fckeditorFeb 8, 2007