CVE Database
/

CVE-2007-2630

Back to search

CVE-2007-2630

Published: May 11, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Incomplete blacklist vulnerability in filemanager/browser/default/connectors/php/config.php in the FCKeditor module, as used in ActiveCampaign 1-2-All (aka 12All) 4.50 through 4.53.13, and possibly other products, allows remote authenticated administrators to upload and possibly execute .php4 and .php5 files via unspecified vectors. NOTE: this issue is reachable through filemanager/browser/default/browser.html.

VendorProductVersions

n/a

n/a

affected
n/a

References

12all-fckeditor-file-upload(34049)
vdb-entry
x_refsource_XF
20070507 Re: 12All File Upload Vulnerability
mailing-list
x_refsource_BUGTRAQ
20070502 12All File Upload Vulnerability
mailing-list
x_refsource_BUGTRAQ
36161
vdb-entry
x_refsource_OSVDB
23792
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now