CVE-2013-2089Owncloud vulnerability

4 documents4 sources
Severity
4.6MEDIUMNVD
EPSS
0.4%
top 39.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 14
Latest updateMay 17

Description

Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the file in /data.

CVSS vector

AV:N/AC:H/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages3 packages

Ubuntuowncloud/owncloud< 6.0.1+dfsg-1ubuntu1
NVDowncloud/owncloud_server5 versions+4

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3pmc-r5wv-mxp3: Incomplete blacklist vulnerability in ownCloud before 52022-05-17
CVEList
CVE-2013-2089: Incomplete blacklist vulnerability in ownCloud before 52014-03-14
OSV
CVE-2013-2089: Incomplete blacklist vulnerability in ownCloud before 52014-03-14
CVE-2013-2089 — Owncloud vulnerability | cvebase