3 results (0.008 seconds)

CVSS: 8.8EPSS: 1%CPEs: 3EXPL: 2

28 Sep 2015 — Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension. Múltiples vulnerabilidades de lista negra incompletas en la funcionalidad de carga de avatar en el archivo manageuser.php en Collabtive versiones anteriores a 2.1, permiten a los usuarios autenticados remotos ejecutar código arbitrario mediante... • https://packetstorm.news/files/id/133736 • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 2

15 May 2014 — Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php. Vulnerabilidad de XSS en Collabtive 1.2 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través del parámetro desc en una acción Add Project (addpro) hacia admin.php. • https://www.exploit-db.com/exploits/33250 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 4

08 May 2014 — SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.php. Vulnerabilidad de inyección SQL en Collabtive 1.2 permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través del parámetro folder en una acción fileview_list hacia manageajax.php. Collabtive version 1.12 suffers from a remote SQL injection vulnerability. • https://packetstorm.news/files/id/126554 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •