packetstormsecurity.org
http://packetstormsecurity.org/1010-exploits/collabtive-xssxsrf.txt CVE-2010-5284
Collabtive 0.65 - Multiple Vulnerabilities
Record summary
CVE-2010-5284 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to manageuser.php, (2) y parameter in a newcal action to manageajax.php, and the (3) pic parameter to thumb.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCollabtive 0.65 - Multiple VulnerabilitiesExploitDB exploitby Anatolia SecurityNot analyzed1 file
References
641805Third-party advisory
http://secunia.com/advisories/41805 anatoliasecurity.com
http://www.anatoliasecurity.com/adv/as-adv-2010-003.txt 15240exploit
http://www.exploit-db.com/exploits/15240 44050vdb entry
http://www.securityfocus.com/bid/44050 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2010-5284