Graffiti CMS Arbitrary File Upload Vulnerability 

It seems the FCKeditor’s bug is the same I discovered in Graffiti CMS. If anyone is interested, the details are published in milw0rm.