PT-2015-6055 · Owncloud · Owncloud Server

Lukas Reschke

·

Publicado

2015-05-02

·

Atualizado

2019-02-07

·

CVE-2015-3013

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ownCloud Server versions prior to 5.0.19 ownCloud Server versions 6.x prior to 6.0.7 ownCloud Server versions 7.x prior to 7.0.5
Description The issue allows remote authenticated users to bypass the file blacklist and upload arbitrary files via a file path with UTF-8 encoding. This can be demonstrated by uploading a .htaccess file.
Recommendations For ownCloud Server versions prior to 5.0.19, update to version 5.0.19 or later. For ownCloud Server versions 6.x prior to 6.0.7, update to version 6.0.7 or later. For ownCloud Server versions 7.x prior to 7.0.5, update to version 7.0.5 or later.

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-3013
DSA-3244-1

Produtos afetados

Owncloud Server