Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-2670

Опубликовано: 17 июн. 2012
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:o-dyn:collabtive:*:*:*:*:*:*:*:*
Версия до 0.7.5 (включая)
cpe:2.3:a:o-dyn:collabtive:0.6.4:*:*:*:*:*:*:*
cpe:2.3:a:o-dyn:collabtive:0.6.5:*:*:*:*:*:*:*
cpe:2.3:a:o-dyn:collabtive:0.7:*:*:*:*:*:*:*

EPSS

Процентиль: 51%
0.00275
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 13 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

debian
больше 13 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated ...

github
больше 3 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

EPSS

Процентиль: 51%
0.00275
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-20