Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-0258

Опубликовано: 17 фев. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Средний

Описание

Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:o-dyn:collabtive:*:*:*:*:*:*:*:*
Версия до 2.1 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

EPSS

Процентиль: 95%
0.16497
Средний

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.

CVSS3: 8.8
debian
почти 6 лет назад

Multiple incomplete blacklist vulnerabilities in the avatar upload fun ...

github
больше 3 лет назад

Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.

EPSS

Процентиль: 95%
0.16497
Средний

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434