Description: Janek Vind has reported a vulnerability in FCKEditor, which potentially can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an error in the handling of file uploads in editor/filemanager/upload/php/upload.php when a filename has multiple file extensions. This can be exploited to upload malicious script files (e.g. a PHP script).
Successful exploitation may allow execution of script code depending on the HTTP server configuration (it requires e.g. an Apache server with the "mod_mime" module installed).
The vulnerability is reported in version 2.4.3. Prior versions may also be affected.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.