Page 2 of 11 results (0.003 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

12 Aug 2009 — Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and using a text/plain MIME type, then accessing it via a direct request to the file in files/, related to (1) the showproject action in managefile.php or (2) the Messages feature. Vulnerabilidad de subida de archivos sin restricción en Collabtive v0.4.8 permite a usuarios remotos autenticados ejecutar código arbitrario mediante la subida de ... • https://www.exploit-db.com/exploits/7076 • CWE-20: Improper Input Validation •