CVE Vulnerabilities

CVE-2007-3163

Published: Jun 11, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658.

Affected Software

NameVendorStart VersionEnd Version
FckeditorFrederico_caldeira_knabben2.4.2 (including)2.4.2 (including)
KnowledgerootUbuntudevel*
KnowledgerootUbuntufeisty*
KnowledgerootUbuntugutsy*
KnowledgerootUbuntuhardy*

References