CVE-2013-1851Owncloud vulnerability

6 documents4 sources
Severity
3.5LOWNVD
EPSS
0.2%
top 61.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateMay 17

Description

Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.13 and 4.5.x before 4.5.8, when the user_migrate application is enabled, allows remote authenticated users to import arbitrary files to the user's account via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages2 packages

NVDowncloud/owncloud4.0.12
NVDowncloud/owncloud_server24 versions+23

🔴Vulnerability Details

2
GHSA
GHSA-gp4j-fr8f-4gm3: Incomplete blacklist vulnerability in lib/migrate2022-05-17
CVEList
CVE-2013-1851: Incomplete blacklist vulnerability in lib/migrate2014-03-14

💬Community

3
Bugzilla
CVE-2013-4461 cumin: filtering table operator not checked, leads to potential SQLi2013-10-07
Bugzilla
CVE-2013-4414 cumin: non-persistent XSS possible due to not escaping set limit form input2013-08-19
Bugzilla
CVE-2013-4405 cumin: CSRF protection does not work2013-08-19
CVE-2013-1851 — Owncloud vulnerability | cvebase