Vulnerabilidad en FCKeditor
|
Vulnerability classification
|
|
Property |
Value |
|
Confidence level |
Oficial |
|
Impact |
Obtener acceso |
|
Dificulty |
Avanzado |
|
Required attacker level |
Acceso remoto sin cuenta a un servicio exotico |
System information
|
|
Property |
Value |
|
Affected manufacturer |
GNU/Linux |
|
Affected software |
FCKeditor, versiones 2.6.7 y anteriores |
Description
|
|
Se ha encontrado una vulnerabilidad de tipo cross-site scripting en la función print_textinputs_var, en el fichero editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php, en el popular editor FCKeditor 2.6.7 y versiones anteriores, que podría permitir a atacantes remotos inyectar scripts o código HTML arbitrario mediante ciertos parámetros. |
Solution
|
|
Actualizar fckeditor a la última versión disponible. |
Standar resources
|
|
Property |
Value |
|
CVE |
CVE-2012-4000 |
|
BID |
54188 |
Other resources
|
Debian Security Advisory DSA-2522-1
http://www.debian.org/security/2012/dsa-2522 |