FCKeditor 'command.php' Arbitrary File Upload Vulnerability(情報元のブックマーク数)

FCKeditorのcommand.phpにファイルをアップロードできる脆弱性が存在するそうです。

FCKeditor is prone to an arbitrary-file-upload vulnerability because it fails to adequately sanitize user-supplied input.

An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.

http://www.securityfocus.com/bid/31812/discuss

screenshot