Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-2670

Опубликовано: 17 июн. 2012
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.5

Описание

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

not-affected

0.7.6-1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [0.7.6-1]]
hardy

DNE

lucid

DNE

natty

DNE

oneiric

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

not-affected

0.7.6-1

Показывать по

EPSS

Процентиль: 51%
0.00275
Низкий

6.5 Medium

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

debian
больше 13 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated ...

github
больше 3 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

EPSS

Процентиль: 51%
0.00275
Низкий

6.5 Medium

CVSS2