Description
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2125-1 | collabtive security update |
Ubuntu USN |
USN-4590-1 | Collabtive vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T04:03:10.663Z
Reserved: 2014-11-18T00:00:00.000Z
Link: CVE-2015-0258
No data.
Status : Modified
Published: 2020-02-17T18:15:11.607
Modified: 2024-11-21T02:22:40.377
Link: CVE-2015-0258
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Ubuntu USN