CVE-2009-2265
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- June 29, 2009
- Published Date
- July 05, 2009
- Last Updated
- August 07, 2024
- Vendor
- FCKeditor
- Product
- FCKeditor
- Description
- Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.
- Tags
- Exploited in the Wild
- Yes (2009-07-05 16:00:00 UTC) Source
CVSS Scores
CVSS v2.0
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploit Status
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CVE | 2009-07-05 16:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/coldfusion_fckeditor.rb | 2025-04-29 11:01:37 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
coldfusion_fckeditor
Type: metasploit • Created: Unknown
0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265
Type: github • Created: 2024-12-18 18:12:56 UTC • Stars: 1
p1ckzi/CVE-2009-2265
Type: github • Created: 2022-01-14 17:34:28 UTC • Stars: 1
n3rdh4x0r/CVE-2009-2265
Type: github • Created: 2021-07-15 23:14:11 UTC • Stars: 1
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Metasploit