CVE-2015-4718OS Command Injection in Owncloud

Severity
9.0CRITICALNVD
EPSS
1.0%
top 23.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 21
Latest updateMay 17

Description

The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages2 packages

NVDowncloud/owncloud_server9 versions+8

🔴Vulnerability Details

2
GHSA
GHSA-x4hm-9x5q-gw23: The external SMB storage driver in ownCloud Server before 62022-05-17
CVEList
CVE-2015-4718: The external SMB storage driver in ownCloud Server before 62015-10-21

💬Community

3
Bugzilla
CVE-2015-4717 CVE-2015-7699 CVE-2015-5954 CVE-2015-5953 CVE-2015-4718 owncloud: Multiple vulnerabilities fixed [fedora-all]2015-10-19
Bugzilla
CVE-2015-4717 CVE-2015-4718 CVE-2015-5953 CVE-2015-5954 CVE-2015-7699 CVE-2015-4716 owncloud: Multiple vulnerabilities fixed2015-10-19
Bugzilla
CVE-2015-4717 CVE-2015-7699 CVE-2015-5954 CVE-2015-5953 CVE-2015-4718 owncloud: Multiple vulnerabilities fixed [epel-all]2015-10-19
CVE-2015-4718 — OS Command Injection in Owncloud | cvebase