CVE-2009-2265
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 84%
from disclosure to weapon507 days
Published on NVDJul 5
1st PoC+507d
metasploitJul 3
VulnCheckJul 5
exploitation probability
84%top 1% of all CVEs
observed exploitation
yesVulnCheck
16 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Not affected
1 product — because the vulnerable code is not present in the product
red_hat_products
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.
Affected products
n/a · n/apublic PoCs found — 16✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16788exploitdbwww.exploit-db.com/exploits/50057unverifiedgithubgithub.com/zaphoxx/zaphoxx-coldfusion★ 2githubgithub.com/p1ckzi/CVE-2009-2265★ 1githubgithub.com/h3x0v3rl0rd/CVE-2009-2265★ 1githubgithub.com/0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265★ 1githubgithub.com/matesz44/CVE-2009-2265★ 0githubgithub.com/hd-exe/CVE-2009-2265-fix★ 0githubgithub.com/nika0x38/CVE-2009-2265★ 0vulncheckvulncheck.com/xdb/fafea7ec3196unverifiedvulncheckvulncheck.com/xdb/6dffa0d10aafunverifiedcve_referencepacketstormsecurity.com/files/163271/Adobe-ColdFusion-8-Remote-Command-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/80b7a130852dunverifiedvulncheckvulncheck.com/xdb/be9af909f6f3unverifiedvulncheckvulncheck.com/xdb/cbd839ecaccfunverifiedvulncheckvulncheck.com/xdb/cef775c3ecfeunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://isc.sans.org/diary.html?storyid=6724http://mail.zope.org/pipermail/zope-dev/2009-July/037195.htmlhttp://packetstormsecurity.com/files/163271/Adobe-ColdFusion-8-Remote-Command-Execution.htmlhttp://secunia.com/advisories/35833http://secunia.com/advisories/35909http://sourceforge.net/project/shownotes.php?release_id=695430https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00710.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00750.htmlhttp://www.debian.org/security/2009/dsa-1836http://www.ocert.org/advisories/ocert-2009-007.htmlhttp://www.securityfocus.com/archive/1/504721/100/0/threadedhttp://www.securitytracker.com/id?1022513