Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains .php. and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cardinal_cms | Cardinal_cms_project | 1.2 (including) | 1.2 (including) |
Lanai_cms | Redlinesoft | * | 1.2.16 (including) |
Sitex_cms | Sitex_cms_project | 0.7.3-beta (including) | 0.7.3-beta (including) |
Syntax_cms | Syntax_cms_project | * | 1.3 (including) |
Knowledgeroot | Ubuntu | devel | * |
Knowledgeroot | Ubuntu | feisty | * |
Knowledgeroot | Ubuntu | gutsy | * |
Knowledgeroot | Ubuntu | hardy | * |