FCKEditor.NET File Renaming Remote Code Execution Weakness
BID:42859
Info
FCKEditor.NET File Renaming Remote Code Execution Weakness
| Bugtraq ID: | 42859 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2010 12:00AM |
| Updated: | Aug 30 2010 12:00AM |
| Credit: | HD_Moore |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
FCKEditor.NET File Renaming Remote Code Execution Weakness
FCKEditor.NET is prone to a security weakness that may allow attackers to execute arbitrary code.
An attacker can exploit this issue in conjunction with other latent vulnerabilities to execute arbitrary code with the privileges of the webserver.
Versions prior to FCKEditor.NET 2.6.4 are vulnerable.
FCKEditor.NET is prone to a security weakness that may allow attackers to execute arbitrary code.
An attacker can exploit this issue in conjunction with other latent vulnerabilities to execute arbitrary code with the privileges of the webserver.
Versions prior to FCKEditor.NET 2.6.4 are vulnerable.
Exploit / POC
FCKEditor.NET File Renaming Remote Code Execution Weakness
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
FCKEditor.NET File Renaming Remote Code Execution Weakness
Solution:
Updates are available to address this issue. Please see the references for more information.
Solution:
Updates are available to address this issue. Please see the references for more information.
References
FCKEditor.NET File Renaming Remote Code Execution Weakness
References:
References:
- FCKEditor Homepage (Frederico Caldeira Knabben)
- FCKeditor.Net 2.6.4 released (FCKeditor)
- R7-0036: FCKEditor.NET File Upload Code Execution (HD Moore
)