manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and...
Vulnerability Description
manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-2670
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/53813
- http://www.collabtive.o-dyn.de/blog/?p=426
- http://archives.neohapsis.com/archives/bugtraq/2012-06/0007.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76101
- http://xync.org/2012/06/04/Arbitrary-File-Upload-in-Collabtive.html
- http://www.securityfocus.com/archive/1/522973/30/0/threaded
- http://www.openwall.com/lists/oss-security/2012/06/06/6
- http://www.openwall.com/lists/oss-security/2012/06/06/9
More from o-dyn
View All →Affected Vendor
o-dyn
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.