CVE-2015-0258: Canonical Ubuntu Linux

High severity, CVSS 8.8. EPSS: 3.8% chance of exploitation in the next 30 days.

Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only
  • Debian Debian Linux: version 8.0 only
  • O-Dyn Collabtive: before 2.1 (fixed in 2.1)

Published 2020-02-17. Last modified 2026-06-17.