exploit the possibilities

Collabtive 2.0 Shell Upload

Collabtive 2.0 Shell Upload
Posted Sep 28, 2015
Authored by Arturo Rodriguez

Collabtive version 2.0 suffers from an arbitrary file upload vulnerability.

tags | exploit, arbitrary, file upload
advisories | CVE-2015-0258
MD5 | 9c6a8438c3abf888bb1b897c4d3d293e

Collabtive 2.0 Shell Upload

Change Mirror Download
Vulnerability title: Arbitrary File Upload In Collabtive
CVE: CVE-2015-0258
Vendor: Collabtive
Product: Collabtive
Affected version: 2.0
Fixed version: 2.1
Reported by: Arturo Rodriguez
Details:

It was discovered that authenticated users were able to upload files with extensions: php3, php4, php5 or phtml to the web server.

The issue is on the avatar upload functionality. The application checks if the filetype is an image but this can be bypassed using a proxy and changing the type to "image/jpeg" on the file upload request. The application also checks if the extension of the file is php or pl but it doesn't check for .php3 .php4 .php5 or phtml. It is possible to upload a file with one of these extensions and get code execution by going to http://installpath/files/standard/avatar/image_name

Even though a random value is appended to the name of the image, it is possible to get the name by seeing the requests the application does when the avatar image is loaded.

Impact:
An attacker could exploit the functionality to upload server scripts which, when requested by a browser, would execute code on the server.

Login or Register to add favorites

File Archive:

May 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    14 Files
  • 2
    May 2nd
    3 Files
  • 3
    May 3rd
    1 Files
  • 4
    May 4th
    18 Files
  • 5
    May 5th
    15 Files
  • 6
    May 6th
    21 Files
  • 7
    May 7th
    15 Files
  • 8
    May 8th
    19 Files
  • 9
    May 9th
    1 Files
  • 10
    May 10th
    2 Files
  • 11
    May 11th
    18 Files
  • 12
    May 12th
    39 Files
  • 13
    May 13th
    15 Files
  • 14
    May 14th
    17 Files
  • 15
    May 15th
    17 Files
  • 16
    May 16th
    2 Files
  • 17
    May 17th
    2 Files
  • 18
    May 18th
    15 Files
  • 19
    May 19th
    21 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    15 Files
  • 22
    May 22nd
    6 Files
  • 23
    May 23rd
    1 Files
  • 24
    May 24th
    1 Files
  • 25
    May 25th
    2 Files
  • 26
    May 26th
    23 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close