CVE Vulnerabilities

CVE-2013-2089

Published: Mar 14, 2014 | Modified: Mar 17, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the file in /data.

Affected Software

Name Vendor Start Version End Version
Owncloud Owncloud * 5.0.5 (including)
Owncloud Owncloud 5.0.0 (including) 5.0.0 (including)
Owncloud Owncloud 5.0.1 (including) 5.0.1 (including)
Owncloud Owncloud 5.0.2 (including) 5.0.2 (including)
Owncloud Owncloud 5.0.3 (including) 5.0.3 (including)
Owncloud Owncloud 5.0.4 (including) 5.0.4 (including)

References