Opened 9 years ago

Closed 9 years ago

#6172 closed Bug (fixed)

Duplicate File Renaming Bug - ASP.NET Connector

Reported by: Willis Owned by:
Priority: Normal Milestone:
Component: Server : ASP.Net Version: FCKeditor 2.5.1
Keywords: Cc:

Description

Hi,

I have noticed a bug in FCKEditor version 2.5.1 and I wanted to confirm if it exists in 2.6.6 or, if not, in which version it was fixed. In reviewing the code it looks as if it may still exist, but I could not confirm.

(...)

I have not verified that this bug exists in any of the other connectors.

The existence of this bug in the ASP.NET connector represents a significant security vulnerability when running on IIS. Please keep this correspondence private. I would prefer to discuss this over e-mail, but I was indicated that this is the location to discuss security issues in the product.

Thank you!

Change History (2)

comment:1 Changed 9 years ago by Wiktor Walc

comment:2 Changed 9 years ago by Wiktor Walc

Resolution: fixed
Status: newclosed

Fixed in FCKeditor.Net 2.6.4.

Please use the contact form next time to report security issues. Thanks!

Note: See TracTickets for help on using tickets.
© 2003 – 2019 CKSource – Frederico Knabben. All rights reserved. | Terms of use | Privacy policy