CVE-2009-2265
CVE-2009-2265
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.
Productos afectados
n/a · n/aPoCs públicas encontradas — 9
githubgithub.com/zaphoxx/zaphoxx-coldfusion★ 2githubgithub.com/h3x0v3rl0rd/CVE-2009-2265★ 1githubgithub.com/p1ckzi/CVE-2009-2265★ 1githubgithub.com/0xDTC/Adobe-ColdFusion-8-RCE-CVE-2009-2265★ 1githubgithub.com/matesz44/CVE-2009-2265★ 0githubgithub.com/nika0x38/CVE-2009-2265★ 0exploitdbwww.exploit-db.com/exploits/16788no verificadoexploitdbwww.exploit-db.com/exploits/50057no verificadocve_referencepacketstormsecurity.com/files/163271/Adobe-ColdFusion-8-Remote-Command-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://isc.sans.org/diary.html?storyid=6724http://mail.zope.org/pipermail/zope-dev/2009-July/037195.htmlhttp://packetstormsecurity.com/files/163271/Adobe-ColdFusion-8-Remote-Command-Execution.htmlhttp://secunia.com/advisories/35833http://secunia.com/advisories/35909http://sourceforge.net/project/shownotes.php?release_id=695430https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00710.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-July/msg00750.htmlhttp://www.debian.org/security/2009/dsa-1836http://www.ocert.org/advisories/ocert-2009-007.htmlhttp://www.securityfocus.com/archive/1/504721/100/0/threadedhttp://www.securitytracker.com/id?1022513