CVE-2012-2670
Summary
| CVE | CVE-2012-2670 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-06-17 03:41:41 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | manageuser.php in Collabtive before 0.7.6 allows remote authenticated users, and possibly unauthenticated attackers, to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg, then accessing it via a direct request to the file in files/standard/avatar. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | O-dyn | Collabtive | 0.6.4 | All | All | All |
| Application | O-dyn | Collabtive | 0.6.5 | All | All | All |
| Application | O-dyn | Collabtive | 0.7 | All | All | All |
| Application | O-dyn | Collabtive | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Collabtive 'manageuser.php' Arbitrary File Upload Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Xync.org | af854a3a-2127-422b-91ae-364da2661108 | xync.org | |
| archives.neohapsis.com/archives/bugtraq/2012-06/0007.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| oss-security - Re: Arbitrary File Upload/Execution in Collabtive | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Collabtive Blog » Blog Archive » Collabtive 0.7.6 released | af854a3a-2127-422b-91ae-364da2661108 | www.collabtive.o-dyn.de | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| oss-security - Arbitrary File Upload/Execution in Collabtive | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.