CVE-2007-3163

Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658.
Configurations

Configuration 1 (hide)

cpe:2.3:a:frederico_caldeira_knabben:fckeditor:2.4.2:*:*:*:*:*:*:*

History

21 Nov 2024, 00:32

Type Values Removed Values Added
References () http://ha.ckers.org/blog/20070606/additional-image-bypass-on-windows/ - () http://ha.ckers.org/blog/20070606/additional-image-bypass-on-windows/ -
References () http://osvdb.org/37554 - () http://osvdb.org/37554 -
References () http://secunia.com/advisories/25719 - () http://secunia.com/advisories/25719 -
References () http://secunia.com/advisories/25923 - () http://secunia.com/advisories/25923 -
References () http://sourceforge.net/project/shownotes.php?release_id=520159 - () http://sourceforge.net/project/shownotes.php?release_id=520159 -
References () http://www.bitchiller.de/?p=20 - URL Repurposed () http://www.bitchiller.de/?p=20 - URL Repurposed
References () http://www.securityfocus.com/bid/24510 - () http://www.securityfocus.com/bid/24510 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/34982 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/34982 -

14 Feb 2024, 01:17

Type Values Removed Values Added
References (MISC) http://www.bitchiller.de/?p=20 - (MISC) http://www.bitchiller.de/?p=20 - URL Repurposed

Information

Published : 2007-06-11 22:30

Updated : 2024-11-21 00:32


NVD link : CVE-2007-3163

Mitre link : CVE-2007-3163

CVE.ORG link : CVE-2007-3163


JSON object : View

Products Affected

frederico_caldeira_knabben

  • fckeditor