CVE-2009-2265 is a directory traversal vulnerability in FCKeditor prior to version 2.6.4.1, affecting multiple products embedding the editor (including Adobe ColdFusion, PHPList, PHP-Nuke, Dokeos, and others). The vulnerability arises from improper input validation in connector modules, particularly the 'CurrentFolder' parameter, allowing remote attackers to upload executable files to arbitrary directories. This can be exploited for remote code execution, as demonstrated in the wild in July 2009.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This two-file repository contains a README and a Python 3 exploit script for CVE-2009-2265 affecting Adobe ColdFusion installations that expose a vulnerable bundled FCKeditor upload connector. poc.py generates a random-named java/jsp_shell_reverse_tcp payload with msfvenom, builds a multipart/form-data request that declares the upload as a .txt file, and sends it to upload.cfm with CurrentFolder ending in .jsp%00. The null byte is intended to cause extension truncation so the server saves a JSP shell. After removing the local generated JSP, the script starts a netcat listener and asynchronously requests the uploaded /userfiles/file/<random>.jsp URL to execute it. The default configuration targets 10.129.110.59:8500 and configures a callback to 10.10.15.222:4444, but these values are explicitly intended to be edited. The repository is a functional offensive exploit rather than a detection-only script; it depends on msfvenom and nc and targets legacy ColdFusion MX 6/7, 8.0/8.0.1, and potentially 9.0 deployments where the vulnerable FCKeditor component remains installed.
Repository contains a single shell script exploit (CVE-2009-2265.sh) targeting Adobe ColdFusion 8 unauthenticated RCE (CVE-2009-2265) via the bundled FCKeditor file manager ColdFusion connector. The script generates a randomized filename (uuidgen lowercased), uses msfvenom to create a java/jsp_shell_reverse_tcp payload, uploads it with curl to the vulnerable upload.cfm endpoint using a null-byte (%00) in the CurrentFolder parameter to force a .jsp filename, deletes the local payload file, then requests /userfiles/file/<name>.jsp to execute it. Primary capability is remote code execution resulting in a reverse shell to attacker-supplied LHOST/LPORT. No additional modules, configuration files, or framework structure are present.
This repository is a Rust-based proof-of-concept exploit for CVE-2009-2265, a remote code execution vulnerability in Adobe ColdFusion 8.0.1 and earlier. The exploit targets the FCKeditor file upload component, specifically the upload.cfm endpoint, which is vulnerable to directory traversal via null byte injection in the 'CurrentFolder' parameter. The exploit generates a JSP reverse shell payload with attacker-supplied IP and port, uploads it to the target using a crafted HTTP POST request, and then triggers the payload by accessing its URL, resulting in a reverse shell connection to the attacker's listener. The repository contains a main Rust source file (src/main.rs), build configuration files (Cargo.toml, Cargo.lock), a .gitignore, and a detailed README explaining the vulnerability, usage, and technical details. The exploit is operational, automating the full attack chain from payload generation to shell access, and is intended for authorized testing and educational purposes only.
This repository contains a proof-of-concept exploit for CVE-2009-2265, targeting Adobe ColdFusion 8.0.1. The exploit is implemented in a single Python script (upload.py) that uploads an arbitrary JSP file to a vulnerable ColdFusion server via a known insecure file upload endpoint. The README provides usage instructions, including how to generate a JSP reverse shell payload and how to execute the exploit. The exploit works by sending a POST request to the /CFIDE/scripts/ajax/FCKeditor/editor/filemanager/connectors/cfm/upload.cfm endpoint, exploiting a null byte injection to upload a file as 'exploit.jsp'. If successful, the payload can be accessed and executed at /userfiles/file/exploit.jsp on the target server, resulting in remote code execution. The repository is structured simply, with one exploit script and a README, and is intended as a standalone proof-of-concept for this vulnerability.
This repository contains a single Metasploit exploit module targeting Adobe ColdFusion 8.0.1's FCKeditor file upload vulnerability (CVE-2009-2265). The exploit abuses the 'CurrentFolder' parameter in the FCKeditor's upload.cfm script to upload a malicious JSP file to the server. After a successful upload, the module sends a GET request to execute the uploaded payload, resulting in remote code execution. The module is weaponized, allowing the attacker to specify a payload (such as a reverse shell) that will be executed on the target. The main endpoints involved are the vulnerable upload.cfm script and the location where the payload is accessed. The code is written in Ruby and is structured as a standard Metasploit module, making it easy to use within the Metasploit framework.
This repository contains a Bash exploit script (CVE-2009-2265) targeting Adobe ColdFusion 8's file upload vulnerability (CVE-2009-2265). The exploit automates the process of generating a JSP reverse shell payload using msfvenom, uploading it to the vulnerable ColdFusion endpoint via a crafted multipart POST request, and then triggering the payload to establish a reverse shell connection back to the attacker's machine. The script requires the attacker to specify their own IP and port (LHOST/LPORT) as well as the target's IP and ColdFusion port (RHOST/RPORT). The README provides detailed usage instructions, requirements, and an overview of the exploit's operation. The main exploit file is a Bash script, and the repository does not use any exploit framework. The exploit is operational, providing a working reverse shell if the target is vulnerable and properly configured.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.