CVE-2013-6872
NONE
Published Jan 21, 201412y ago · Modified Jun 17, 20262w ago
Published Jan 21, 2014 12y ago
Last Modified Jun 17, 2026 2w ago
Description
SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action.
Threat Intelligence
No active exploitation signals — not in CISA KEV and no EPSS score yet.
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-89 SQL Injection Injection
Affected Products 26
| Vendor | Product | Version | Range |
|---|---|---|---|
| o-dyn | collabtive | * | ≤1.1 |
| o-dyn | collabtive | 0.1 | any |
| o-dyn | collabtive | 0.2 | any |
| o-dyn | collabtive | 0.2.5 | any |
| o-dyn | collabtive | 0.3 | any |
| o-dyn | collabtive | 0.3.5 | any |
| o-dyn | collabtive | 0.3.6 | any |
| o-dyn | collabtive | 0.4 | any |
| o-dyn | collabtive | 0.4.5 | any |
| o-dyn | collabtive | 0.4.6 | any |
| o-dyn | collabtive | 0.4.7 | any |
| o-dyn | collabtive | 0.4.8 | any |
| o-dyn | collabtive | 0.4.9 | any |
| o-dyn | collabtive | 0.4.9.1 | any |
| o-dyn | collabtive | 0.5.1 | any |
| o-dyn | collabtive | 0.5.5 | any |
| o-dyn | collabtive | 0.6 | any |
| o-dyn | collabtive | 0.6.1 | any |
| o-dyn | collabtive | 0.6.2 | any |
| o-dyn | collabtive | 0.6.3 | any |
| o-dyn | collabtive | 0.6.4 | any |
| o-dyn | collabtive | 0.6.5 | any |
| o-dyn | collabtive | 0.7 | any |
| o-dyn | collabtive | 0.7.5 | any |
| o-dyn | collabtive | 0.7.6 | any |
| o-dyn | collabtive | 1.0 | any |
References 6
- osvdb.org http://osvdb.org/102123
- packetstormsecurity.com http://packetstormsecurity.com/files/124777/Collabtive-1.1-SQL-Injection.html
- seclists.org http://seclists.org/fulldisclosure/2014/Jan/72
- collabtive.o-dyn.de http://www.collabtive.o-dyn.de/blog/?p=621#more-621
- exploit-db.com http://www.exploit-db.com/exploits/30946
- securityfocus.com http://www.securityfocus.com/bid/64943
Remediation
- collabtive.o-dyn.de http://www.collabtive.o-dyn.de/blog/?p=621#more-621