Cross-site Scripting Vulnerability in FCKEditor by CKSource
CVE-2006-6978

Currently unrated

Key Information:

Vendor
Fckeditor
Status
Vendor
CVE Published:
8 February 2007

Summary

A cross-site scripting vulnerability exists in the 'Basic Toolbar Selection' feature of FCKEditor, which may allow remote attackers to inject and execute arbitrary JavaScript code. This can be done through manipulations of the javascript: URI in the href or onmouseover attributes of the anchor HTML tag. Such exploitation can lead to unauthorized actions performed on behalf of users.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.