CVE-2009-2265 describes multiple directory traversal vulnerabilities in FCKeditor versions prior to 2.6.4.1, specifically impacting its file browser and connector modules. This flaw allows remote attackers to upload and create executable files in arbitrary directories, leading to remote code execution. With a CVSS score of 7.5 (High) and an EPSS score of 0.93, this vulnerability is easily exploitable over the network with low complexity, potentially resulting in partial confidentiality, integrity, and availability compromise. Exploitation was observed in the wild in July 2009, and Metasploit modules and ExploitDB entries confirm readily available exploit code, despite a lack of recent community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.6.4CPE matchmatch criteria | cpe:2.3:a:fckeditor:fckeditor:*:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:fckeditor:fckeditor:2.0:*:*:*:*:*:*:* | ||
2.0_fcCPE matchmatch criteria | cpe:2.3:a:fckeditor:fckeditor:2.0_fc:*:*:*:*:*:*:* | ||
2.0_rc2CPE matchmatch criteria | cpe:2.3:a:fckeditor:fckeditor:2.0_rc2:*:*:*:*:*:*:* | ||
2.0rc2CPE matchmatch criteria | cpe:2.3:a:fckeditor:fckeditor:2.0rc2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.