CVE-2012-2670
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.
manageuser.php en Collabtive anteriores a v0.7.6 permite a usuarios remotos autenticados, y posiblemente a los atacantes no autenticados, eludir las restricciones de acceso previstas, y subir y ejecutar archivos arbitrarios mediante la subida de un archivo de avatar con un Content-Type validado como image/jpeg, para a continuación, acceder a a través de una solicitud directa al archivo en /standard/avatar.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-05-14 CVE Reserved
- 2012-06-17 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2012-06/0007.html | Mailing List | |
http://www.collabtive.o-dyn.de/blog/?p=426 | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2012/06/06/6 | Mailing List | |
http://www.openwall.com/lists/oss-security/2012/06/06/9 | Mailing List | |
http://www.securityfocus.com/archive/1/522973/30/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/53813 | Vdb Entry | |
http://xync.org/2012/06/04/Arbitrary-File-Upload-in-Collabtive.html | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/76101 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
O-dyn Search vendor "O-dyn" | Collabtive Search vendor "O-dyn" for product "Collabtive" | <= 0.7.5 Search vendor "O-dyn" for product "Collabtive" and version " <= 0.7.5" | - |
Affected
| ||||||
O-dyn Search vendor "O-dyn" | Collabtive Search vendor "O-dyn" for product "Collabtive" | 0.6.4 Search vendor "O-dyn" for product "Collabtive" and version "0.6.4" | - |
Affected
| ||||||
O-dyn Search vendor "O-dyn" | Collabtive Search vendor "O-dyn" for product "Collabtive" | 0.6.5 Search vendor "O-dyn" for product "Collabtive" and version "0.6.5" | - |
Affected
| ||||||
O-dyn Search vendor "O-dyn" | Collabtive Search vendor "O-dyn" for product "Collabtive" | 0.7 Search vendor "O-dyn" for product "Collabtive" and version "0.7" | - |
Affected
|