CVE-2007-3163
Estado: ModificadaMedia (5)—
Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.51%
- Percentil entre todas las CVEs puntuadas: 74
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://ha.ckers.org/blog/20070606/additional-image-bypass-on-windows/
- http://osvdb.org/37554
- http://secunia.com/advisories/25719
- http://secunia.com/advisories/25923
- http://sourceforge.net/project/shownotes.php?release_id=520159
- http://www.bitchiller.de/?p=20
- http://www.securityfocus.com/bid/24510
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34982
- http://ha.ckers.org/blog/20070606/additional-image-bypass-on-windows/
- http://osvdb.org/37554
- http://secunia.com/advisories/25719
- http://secunia.com/advisories/25923
- http://sourceforge.net/project/shownotes.php?release_id=520159
- http://www.bitchiller.de/?p=20
- http://www.securityfocus.com/bid/24510
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34982
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-3163",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-06-11T22:30:00.000",
"references": [
{
"url": "http://ha.ckers.org/blog/20070606/additional-image-bypass-on-windows/",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/37554",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25719",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/25923",
"source": "cve@mitre.org"
},
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=520159",
"source": "cve@mitre.org"
},
{
"url": "http://www.bitchiller.de/?p=20",
"tags": [
"URL Repurposed"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/24510",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34982",
"source": "cve@mitre.org"
},
{
"url": "http://ha.ckers.org/blog/20070606/additional-image-bypass-on-windows/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/37554",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25719",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/25923",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://sourceforge.net/project/shownotes.php?release_id=520159",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.bitchiller.de/?p=20",
"tags": [
"URL Repurposed"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/24510",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34982",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658."
},
{
"lang": "es",
"value": "Vulnerabilidad de lista negra incompleta en el gestor de ficheros en Frederico Caldeira Knabben FCKeditor 2.4.2 permite a atacantes remotos actualizar archivos .php de su elección a través de sintaxis alterna de secuencia de datos, como se demostró por el nombre de fichero .php::$DATA, relacionado con el asunto en CVE-2006-0658."
}
],
"lastModified": "2026-06-16T22:41:11.503",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:frederico_caldeira_knabben:fckeditor:2.4.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADF90214-948D-4823-B16E-B30285C8BA09"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}