Loading
editor/filemanager/upload/php/upload.php in FCKeditor before 2.3 Beta, when the upload feature is enabled, does not verify the Type parameter, which allows remote attackers to upload arbitrary file types. NOTE: It is not clear whether this is related to CVE-2006-0658.
Use Fckeditor vendor hub and Fckeditor product page to widen CVE-2006-2529 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2009-2265, CVE-2008-6178 and CVE-2006-0921 for nearby disclosures in the same product family.