FCKeditor 'CurrentFolder' Parameter Arbitrary File Upload Vulnerability
BID:31812
Info
FCKeditor 'CurrentFolder' Parameter Arbitrary File Upload Vulnerability
| Bugtraq ID: | 31812 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6178 CVE-2009-2265 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | EgiX and Batter |
| Vulnerable: |
Zope Zope.html 1.1 xtcModified eCommerce Shopsoftware xtcModified 1.04 Tru-Zone NukeET 3.4 PHPList PHPList 2.10.6 PHPList PHPList 2.10.5 PHPList PHPList 2.10.4 PHPList PHPList 2.10.3 PHPList PHPList 2.10.2 PHPList PHPList 2.10.1 PHP-Nuke PHP-Nuke 8.2 Nakid Nakid CMS 0.5.2 Knowledgeroot Knowledgebase 0.9.9 5 FCKeditor FCKeditor 2.6.4 FCKeditor FCKeditor 2.4.3 FCKeditor FCKeditor 2.0 rc3 FCKeditor FCKeditor 2.0 RC2 FCKeditor FCKeditor 2.3 beta FCKeditor FCKeditor 2.2 Falt4 CMS Falt4 Extreme RC4 Dokeos Dokeos 1.8.6 Dokeos Dokeos 1.8.5 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Clansphere Clansphere 2009.0.1 Clansphere Clansphere 2008.2.1 Clansphere Clansphere 2009.0 Clansphere Clansphere 2008 Alexscriptengine News-Engine 1.5.1 Alexscriptengine Article-Engine 1.3 Adobe ColdFusion 8.0.1 Adobe ColdFusion 8.0 |
| Not Vulnerable: |
Zope Zope.html 1.2 PHPList PHPList 2.10.7 FCKeditor FCKeditor 2.6.4 .1 Clansphere Clansphere 2009.0.2 |
Discussion
FCKeditor 'CurrentFolder' Parameter Arbitrary File Upload Vulnerability
FCKeditor is prone to a vulnerability that lets attackers upload arbitrary files it fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Versions prior to FCKeditor 2.6.4.1 are vulnerable.
FCKeditor is prone to a vulnerability that lets attackers upload arbitrary files it fails to adequately sanitize user-supplied input.
An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
Versions prior to FCKeditor 2.6.4.1 are vulnerable.
Exploit / POC
FCKeditor 'CurrentFolder' Parameter Arbitrary File Upload Vulnerability
Attackers may exploit this issue via a browser.
Reports indicate that this issue is being exploited in the wild.
The following exploits are available:
Attackers may exploit this issue via a browser.
Reports indicate that this issue is being exploited in the wild.
The following exploits are available:
Solution / Fix
FCKeditor 'CurrentFolder' Parameter Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-64
Debian Linux 5.0 alpha
Debian Linux 5.0 ia-32
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
FCKeditor FCKeditor 2.2
Debian Linux 5.0 hppa
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Debian Linux 5.0 armel
Debian Linux 5.0
Debian Linux 5.0 amd64
FCKeditor FCKeditor 2.3 beta
Debian Linux 5.0 mips
Debian Linux 5.0 powerpc
Debian Linux 5.0 sparc
FCKeditor FCKeditor 2.0 rc3
FCKeditor FCKeditor 2.0 RC2
FCKeditor FCKeditor 2.4.3
FCKeditor FCKeditor 2.6.4
Solution:
Updates are available. Please see the references for more information.
Debian Linux 5.0 ia-64
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 alpha
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 ia-32
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 s/390
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 mipsel
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
FCKeditor FCKeditor 2.2
-
FCKeditor FCKeditor_2.6.4.1.tar.gz
http://prdownloads.sourceforge.net/fckeditor/FCKeditor_2.6.4.1.tar.gz? download
Debian Linux 5.0 hppa
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 m68k
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 arm
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 armel
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 amd64
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
FCKeditor FCKeditor 2.3 beta
-
FCKeditor FCKeditor_2.6.4.1.tar.gz
http://prdownloads.sourceforge.net/fckeditor/FCKeditor_2.6.4.1.tar.gz? download
Debian Linux 5.0 mips
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 powerpc
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
Debian Linux 5.0 sparc
-
Debian fckeditor_2.6.2-1lenny1_all.deb
http://security.debian.org/pool/updates/main/f/fckeditor/fckeditor_2.6 .2-1lenny1_all.deb
FCKeditor FCKeditor 2.0 rc3
-
FCKeditor FCKeditor_2.6.4.1.tar.gz
http://prdownloads.sourceforge.net/fckeditor/FCKeditor_2.6.4.1.tar.gz? download
FCKeditor FCKeditor 2.0 RC2
-
FCKeditor FCKeditor_2.6.4.1.tar.gz
http://prdownloads.sourceforge.net/fckeditor/FCKeditor_2.6.4.1.tar.gz? download
FCKeditor FCKeditor 2.4.3
-
FCKeditor FCKeditor_2.6.4.1.tar.gz
http://prdownloads.sourceforge.net/fckeditor/FCKeditor_2.6.4.1.tar.gz? download
FCKeditor FCKeditor 2.6.4
-
FCKeditor FCKeditor_2.6.4.1.tar.gz
http://prdownloads.sourceforge.net/fckeditor/FCKeditor_2.6.4.1.tar.gz? download
References
FCKeditor 'CurrentFolder' Parameter Arbitrary File Upload Vulnerability
References:
References:
- [Zope-dev] zope.html with FCKEditor security fix (Zope)
- Alex Script Engine Homepage (Alexscriptengine)
- ClanSphere 2009.0.2 Changelog (ClanSphere)
- Dokeos 1.8 Security patch (Dokeos)
- FCKeditor - What's New? (FCKeditor)
- FCKeditor Home Page (FCKeditor)
- FCKeditor Releases Version 2.6.4.1 (US-CERT)
- Nakid CMS Homepage (Nakid)
- PHPList Homepage (PHPList)
- Potential ColdFusion security issue (Adobe)
- Tru-Zone Homepage (Tru-Zone)
- [oCERT-2009-007] FCKeditor input sanitization errors (Andrea Barisani
) - #2009-007 FCKeditor input sanitization errors (oCERT)
- APSB09-09 Hotfix available for potential ColdFusion 8 input sanitization issue (Adobe)