CVE-2009-2265
Summary
| CVE | CVE-2009-2265 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-07-05 16:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Fckeditor | Fckeditor | 2.0 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.0rc2 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.0rc3 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.0_fc | All | All | All |
| Application | Fckeditor | Fckeditor | 2.0_rc2 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.1 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.1.1 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.2 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.3 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.3 | beta | All | All |
| Application | Fckeditor | Fckeditor | 2.3.1 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.3.2 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.3.3 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.4 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.4.1 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.4.2 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.4.3 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.5 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.5 | beta | All | All |
| Application | Fckeditor | Fckeditor | 2.5.1 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.6 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.6.1 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.6.2 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.6.3 | All | All | All |
| Application | Fckeditor | Fckeditor | 2.6.3 | beta | All | All |
| Application | Fckeditor | Fckeditor | 2.6.4 | beta | All | All |
| Application | Fckeditor | Fckeditor | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 11 Update: moin-1.8.4-2.fc11 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SourceForge.net: ClanSphere: Files | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| SecurityTracker.com Archives - FCKeditor input Validation Flaw Lets Remote Users Upload Arbitrary Files | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Fedora update for moin - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| FCKEditor advisory | af854a3a-2127-422b-91ae-364da2661108 | isc.sans.org | |
| oCERT.org - oCERT Advisories | af854a3a-2127-422b-91ae-364da2661108 | www.ocert.org | Patch |
| Debian -- Security Information -- DSA-1836-1 fckeditor | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| [Zope-dev] zope.html with FCKEditor security fix | af854a3a-2127-422b-91ae-364da2661108 | mail.zope.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Debian update for fckeditor - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [SECURITY] Fedora 10 Update: moin-1.6.4-3.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Adobe ColdFusion 8 Remote Command Execution ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.