Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.
Link | Tags |
---|---|
http://securityreason.com/securityalert/484 | third party advisory |
http://www.nsag.ru/vuln/952.html | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24878 | vdb entry |
http://www.securityfocus.com/archive/1/434559/30/4890/threaded | mailing list |
http://www.securityfocus.com/archive/1/425937/100/0/threaded | mailing list |