CVE-2009-2265Exploit(fckeditor / fckeditor)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for fckeditor fckeditor systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fckeditor

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-03-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fckeditor

23 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-12: 1Mentions · 2026-08-29: 1PoC Mentioned / Linked · 2026-08-29: 1Exploit Tool / Code · 2026-03-12: 1Exploit Tool / Code · 2026-08-29: 1Technical Details · 2026-03-12: 1Technical Details · 2026-08-29: 103-1208-29
Signal classification1 categories
Exploit
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Ch4rl3s K00m3@CharlesKoome6
    Exploit

    Just popped Arctic on HTB Old ColdFusion 8 → CVE-2009-2265 RCE → shell as arctic\tolis. I upgraded to Meterpreter, migrated x86→x64, then used MS16-075 (Juicy Potato/DCOM NTLM reflection) to escalate to SYSTEM. https://blog.charleskoome.com/posts/arctic-hackthebox-writeup/ #HTB #InfoSec #Pentesting #Windows

    Post summary

    The writeup demonstrates a successful exploitation of ColdFusion 8 CVE‑2009‑2265 RCE, achieving a shell and escalating privileges to SYSTEM using the Juicy Potato exploit.

    00041377
    1.2K followersView on X
  • TL;DR CTF with Onurcan@CtfWithOG
    Exploit

    4/10 searchsploit coldfusion 8 Hit: CVE-2009-2265 Unauthenticated RCE via FCKeditor file upload endpoint. Exploit auto-generates a .jsp reverse shell via msfvenom, uploads it, triggers execution. No auth required.

    Post summary

    The note highlights an Unauthenticated RCE in ColdFusion 8 (CVE‑2009‑2265), detailing a functional exploit that auto‑generates a JSP reverse shell using msfvenom. No patch or active exploitation information is provided.

    1000052
    4 followersView on X
CPE platform detail27 entries

27 of 27 entries

PartVendorProductVersionTarget SWTarget HW
Appfckeditorfckeditor---
Appfckeditorfckeditor2.0--
Appfckeditorfckeditor2.0_fc--
Appfckeditorfckeditor2.0_rc2--
Appfckeditorfckeditor2.0rc2--
Appfckeditorfckeditor2.0rc3--
Appfckeditorfckeditor2.1--
Appfckeditorfckeditor2.1.1--
Appfckeditorfckeditor2.2--
Appfckeditorfckeditor2.3--
Appfckeditorfckeditor2.3--
Appfckeditorfckeditor2.3.1--
Appfckeditorfckeditor2.3.2--
Appfckeditorfckeditor2.3.3--
Appfckeditorfckeditor2.4--
Appfckeditorfckeditor2.4.1--
Appfckeditorfckeditor2.4.2--
Appfckeditorfckeditor2.4.3--
Appfckeditorfckeditor2.5--
Appfckeditorfckeditor2.5--
Appfckeditorfckeditor2.5.1--
Appfckeditorfckeditor2.6--
Appfckeditorfckeditor2.6.1--
Appfckeditorfckeditor2.6.2--
Appfckeditorfckeditor2.6.3--
Appfckeditorfckeditor2.6.3--
Appfckeditorfckeditor2.6.4--

Explore more