Loading
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions that are not listed in the Config[DeniedExtensions][File], such as .php.txt.
Cite this page
CVE-2006-0658. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2006-0658
Use Fckeditor vendor hub and Fckeditor product page to widen CVE-2006-0658 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2009-2265, CVE-2008-6178 and CVE-2006-0921 for nearby disclosures in the same product family.