// For flags

CVE-2012-2670

 

Severity Score

6.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.

manageuser.php en Collabtive anteriores a v0.7.6 permite a usuarios remotos autenticados, y posiblemente a los atacantes no autenticados, eludir las restricciones de acceso previstas, y subir y ejecutar archivos arbitrarios mediante la subida de un archivo de avatar con un Content-Type validado como image/jpeg, para a continuación, acceder a a través de una solicitud directa al archivo en /standard/avatar.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-05-14 CVE Reserved
  • 2012-06-17 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
O-dyn
Search vendor "O-dyn"
Collabtive
Search vendor "O-dyn" for product "Collabtive"
<= 0.7.5
Search vendor "O-dyn" for product "Collabtive" and version " <= 0.7.5"
-
Affected
O-dyn
Search vendor "O-dyn"
Collabtive
Search vendor "O-dyn" for product "Collabtive"
0.6.4
Search vendor "O-dyn" for product "Collabtive" and version "0.6.4"
-
Affected
O-dyn
Search vendor "O-dyn"
Collabtive
Search vendor "O-dyn" for product "Collabtive"
0.6.5
Search vendor "O-dyn" for product "Collabtive" and version "0.6.5"
-
Affected
O-dyn
Search vendor "O-dyn"
Collabtive
Search vendor "O-dyn" for product "Collabtive"
0.7
Search vendor "O-dyn" for product "Collabtive" and version "0.7"
-
Affected