CVE-2009-2324
Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitrary web script or HTML via components in the samples (aka _samples) directory.
- Affected products
- Ckeditor
- Fckeditor
- ≤ 2.6.4, 2.0, 2.0_fc, 2.0_rc2, 2.0rc2, 2.0rc3, 2.1, 2.1.1, 2.2, 2.3, 2.3.1, 2.3.2, 2.3.3, 2.4, 2.4.1, 2.4.2, 2.4.3, 2.5, 2.5.1, 2.6, 2.6.1, 2.6.2, 2.6.3
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2009-07-05
CVE-2009-2324 at NVD
1 known exploit for CVE-2009-2324
Proof-of-concept code and exploit modules indexed by Sploitus