Collabtive Multiple Remote Vulnerabilities
BID:32229
Info
Collabtive Multiple Remote Vulnerabilities
| Bugtraq ID: | 32229 |
| Class: | Unknown |
| CVE: |
CVE-2008-6947 CVE-2008-6948 CVE-2008-6946 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | Antonio "s4tan" Parata, Francesco "ascii" Ongaro and Giovanni "evilaliv3" Pellerano. |
| Vulnerable: |
Collabtive Collabtive 0.4.8 |
| Not Vulnerable: | |
Discussion
Collabtive Multiple Remote Vulnerabilities
Collabtive is prone to multiple remote vulnerabilities, including:
- An HTML-injection vulnerability
- An arbitrary-file-upload vulnerability
- An authentication-bypass vulnerability
- An information-disclosure vulnerability
A successful exploit of these issues may allow an attacker to obtain sensitive information, execute arbitrary script code within the context of the browser, steal cookie-based authentication credentials, gain unauthorized access to the affected application, compromise the application, and execute arbitrary script code within the context of the webserver process. Other attacks are also possible.
Collabtive 0.4.8 is vulnerable; other versions may also be affected.
Collabtive is prone to multiple remote vulnerabilities, including:
- An HTML-injection vulnerability
- An arbitrary-file-upload vulnerability
- An authentication-bypass vulnerability
- An information-disclosure vulnerability
A successful exploit of these issues may allow an attacker to obtain sensitive information, execute arbitrary script code within the context of the browser, steal cookie-based authentication credentials, gain unauthorized access to the affected application, compromise the application, and execute arbitrary script code within the context of the webserver process. Other attacks are also possible.
Collabtive 0.4.8 is vulnerable; other versions may also be affected.
Exploit / POC
Collabtive Multiple Remote Vulnerabilities
An attacker can exploit these issues using readily available tools. To exploit an HTML-injection issue, the attacker must entice an unsuspecting user to view an affected page.
An attacker can exploit these issues using readily available tools. To exploit an HTML-injection issue, the attacker must entice an unsuspecting user to view an affected page.
Solution / Fix
Collabtive Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Collabtive Multiple Remote Vulnerabilities
References:
References:
- Collabtive Homepage (Collabtive)
- Collabtive 0.4.8 Multiple Vulnerabilities (ascii
)