cve/2006/CVE-2006-0921.md
2024-06-18 02:51:15 +02:00

744 B

CVE-2006-0921

Description

Multiple directory traversal vulnerabilities in connector.php in FCKeditor 2.0 FC, as used in products such as RunCMS, allow remote attackers to list and create arbitrary directories via a .. (dot dot) in the CurrentFolder parameter to (1) GetFoldersAndFiles and (2) CreateFolder.

POC

Reference

Github

No PoCs found on GitHub currently.