Логотип exploitDog
bind:CVE-2012-2670
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-2670

Количество 4

Количество 4

ubuntu логотип

CVE-2012-2670

больше 13 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2012-2670

больше 13 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2012-2670

больше 13 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated ...

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-5j3c-768x-m8c6

больше 3 лет назад

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-2670

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-2670

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
debian логотип
CVE-2012-2670

manageuser.php in Collabtive before 0.7.6 allows remote authenticated ...

CVSS2: 6.5
0%
Низкий
больше 13 лет назад
github логотип
GHSA-5j3c-768x-m8c6

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу