5
CVSSv2

CVE-2013-1939

Published: 14/03/2014 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The HTML\Browser plugin in SabreDAV prior to 1.6.9, 1.7.x prior to 1.7.7, and 1.8.x prior to 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote malicious users to read arbitrary files via a \ (backslash) character.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fruux sabredav

owncloud owncloud