lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-Id: <201212112356.qBBNuov1013640@sf01web1.securityfocus.com> Date: Tue, 11 Dec 2012 23:56:50 GMT From: bugreport@...uard.info To: bugtraq@...urityfocus.com Subject: FCKEditor File Upload Vulnerability - Description: There is no validation on the extensions when FCKEditor 2.6.8 ASP version is dealing with the duplicate files. As a result, it is possible to bypass the protection and upload a file with any extension. - Reference: http://www.exploit-db.com/exploits/23005/ vulnerable versions: prior to 2.6.9 Vendor Response: http://ckeditor.com/forums/Announcements/FCKeditor-2.6.9-Released