CVE-2009-2265

EUVD-2009-2261
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
fckeditorfckeditor
𝑥
≤ 2.6.4
fckeditorfckeditor
2.0
fckeditorfckeditor
2.0_fc:_fc
fckeditorfckeditor
2.0_rc2:_rc2
fckeditorfckeditor
2.0rc2:rc2
fckeditorfckeditor
2.0rc3:rc3
fckeditorfckeditor
2.1
fckeditorfckeditor
2.1.1
fckeditorfckeditor
2.2
fckeditorfckeditor
2.3
fckeditorfckeditor
2.3:beta
fckeditorfckeditor
2.3.1
fckeditorfckeditor
2.3.2
fckeditorfckeditor
2.3.3
fckeditorfckeditor
2.4
fckeditorfckeditor
2.4.1
fckeditorfckeditor
2.4.2
fckeditorfckeditor
2.4.3
fckeditorfckeditor
2.5
fckeditorfckeditor
2.5:beta
fckeditorfckeditor
2.5.1
fckeditorfckeditor
2.6
fckeditorfckeditor
2.6.1
fckeditorfckeditor
2.6.2
fckeditorfckeditor
2.6.3
fckeditorfckeditor
2.6.3:beta
fckeditorfckeditor
2.6.4:beta
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fckeditor
dapper
dne
hardy
ignored
intrepid
Fixed 1:2.6.2-1lenny1build0.8.10.1
released
jaunty
ignored
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
moin
dapper
not-affected
hardy
not-affected
intrepid
not-affected
jaunty
not-affected
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
References