GreyWolf
Elite Member
- Aug 17, 2009
- 1,862
- 5,847
I use the slimstat plugin on one of my websites that uses wordpress for a platform. Today I noticed some strange activity in the activity log for the website. There was a whole slew of page requests from ip 192.187.111.114
/webmanage/fckeditor/editor/filemanager/connectors/test.html
/editor/filemanager/browser/default/connectors/test.html
/webeditor/editor/filemanager/browser/default/connectors/test.html
/editor/editor/filemanager/connectors/test.html
/manage/fckeditor/editor/filemanager/browser/default/connectors/test.html
/webeditor/editor/filemanager/connectors/test.html
/editor/editor/filemanager/browser/default/connectors/test.html
/admin/fckeditor/editor/filemanager/connectors/test.html
/fckeditor/editor/filemanager/connectors/test.html
/fckeditor/editor/filemanager/browser/default/connectors/test.html
/admin/fckeditor/editor/filemanager/browser/default/connectors/test.html
These all received 404 errors, but it looks like someone was really wanting to find fckeditor. It made me wonder if someone was searching for some kind of vulnerabilty.
Is there some kind of known vulnerability that can be taken advantage of with fckeditor? Has anyone else come across something like this in their logs? Just curious about it.
/webmanage/fckeditor/editor/filemanager/connectors/test.html
/editor/filemanager/browser/default/connectors/test.html
/webeditor/editor/filemanager/browser/default/connectors/test.html
/editor/editor/filemanager/connectors/test.html
/manage/fckeditor/editor/filemanager/browser/default/connectors/test.html
/webeditor/editor/filemanager/connectors/test.html
/editor/editor/filemanager/browser/default/connectors/test.html
/admin/fckeditor/editor/filemanager/connectors/test.html
/fckeditor/editor/filemanager/connectors/test.html
/fckeditor/editor/filemanager/browser/default/connectors/test.html
/admin/fckeditor/editor/filemanager/browser/default/connectors/test.html
These all received 404 errors, but it looks like someone was really wanting to find fckeditor. It made me wonder if someone was searching for some kind of vulnerabilty.
Is there some kind of known vulnerability that can be taken advantage of with fckeditor? Has anyone else come across something like this in their logs? Just curious about it.