Back
CVE-2006-0658
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
Published: Feb 13, 2006
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| fckeditor | fckeditor | 2.0 |
| fckeditor | fckeditor | 2.2 |
GitHub Security Advisory GHSA-mc7h-j7fr-g6h8
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products...
References (10)
- http://retrogod.altervista.org/fckeditor_22_xpl.html Exploit
- http://secunia.com/advisories/18767 Vendor Advisory
- http://www.securityfocus.com/archive/1/424708 Exploit
- http://www.vupen.com/english/advisories/2006/0502 Vendor Advisory
- https://www.exploit-db.com/exploits/3702
- http://retrogod.altervista.org/fckeditor_22_xpl.html Exploit
- http://secunia.com/advisories/18767 Vendor Advisory
- http://www.securityfocus.com/archive/1/424708 Exploit
- http://www.vupen.com/english/advisories/2006/0502 Vendor Advisory
- https://www.exploit-db.com/exploits/3702
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
6.90%
Top 6% most likely to be exploited
Threat Score
22.1 / 100
Data Sources
NVD
EPSS
GitHub