Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-2670

Опубликовано: 17 июн. 2012
Источник: debian
EPSS Низкий

Описание

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
collabtivefixed0.7.6-1package

Примечания

  • http://www.securityfocus.com/archive/1/522973/30/0/threaded

  • http://xync.org/2012/06/04/Arbitrary-File-Upload-in-Collabtive.html

  • http://www.collabtive.o-dyn.de/blog/?p=426

EPSS

Процентиль: 51%
0.00275
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

nvd
больше 13 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

github
больше 3 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

EPSS

Процентиль: 51%
0.00275
Низкий