|
FCKeditor Alternative Data Stream Arbitrary File Upload Vulnerability
FCKeditor is prone to an arbitrary file-upload vulnerability because the application fails to sufficiently sanitize user-supplied input. Attackers can exploit this vulnerability to upload arbitrary PHP files and execute it in the context of the webserver process. This issue affects FCKeditor 2.4.3; other versions may also be affected. |
|
|
Privacy Statement |