CVE Vulnerabilities

CVE-2013-1851

Published: Mar 14, 2014 | Modified: Mar 26, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.13 and 4.5.x before 4.5.8, when the user_migrate application is enabled, allows remote authenticated users to import arbitrary files to the users account via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Owncloud Owncloud * 4.0.12 (including)
Owncloud Owncloud 3.0.0 (including) 3.0.0 (including)
Owncloud Owncloud 3.0.1 (including) 3.0.1 (including)
Owncloud Owncloud 3.0.2 (including) 3.0.2 (including)
Owncloud Owncloud 3.0.3 (including) 3.0.3 (including)
Owncloud Owncloud 4.0.0 (including) 4.0.0 (including)
Owncloud Owncloud 4.0.1 (including) 4.0.1 (including)
Owncloud Owncloud 4.0.2 (including) 4.0.2 (including)
Owncloud Owncloud 4.0.3 (including) 4.0.3 (including)
Owncloud Owncloud 4.0.4 (including) 4.0.4 (including)
Owncloud Owncloud 4.0.5 (including) 4.0.5 (including)
Owncloud Owncloud 4.0.6 (including) 4.0.6 (including)
Owncloud Owncloud 4.0.7 (including) 4.0.7 (including)
Owncloud Owncloud 4.0.8 (including) 4.0.8 (including)
Owncloud Owncloud 4.0.9 (including) 4.0.9 (including)
Owncloud Owncloud 4.0.10 (including) 4.0.10 (including)
Owncloud Owncloud 4.0.11 (including) 4.0.11 (including)
Owncloud Ubuntu oneiric *
Owncloud Ubuntu quantal *
Owncloud Ubuntu raring *
Owncloud Ubuntu saucy *

References