7.5
CVSSv2

CVE-2014-2044

Published: 06/10/2014 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud prior to 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

Vulnerable Product Search on Vulmon Subscribe to Product

owncloud owncloud 4.5.7

owncloud owncloud 4.5.6

owncloud owncloud 4.5.5

owncloud owncloud 4.5.10

owncloud owncloud 4.5.1

owncloud owncloud 4.0.4

owncloud owncloud 4.0.3

owncloud owncloud 4.0.10

owncloud owncloud 4.0.1

owncloud owncloud 4.5.4

owncloud owncloud 4.5.3

owncloud owncloud 4.5.0

owncloud owncloud 4.0.9

owncloud owncloud 4.0.2

owncloud owncloud 4.0.16

owncloud owncloud 4.0.0

owncloud owncloud 3.0.3

owncloud owncloud 4.5.2

owncloud owncloud

owncloud owncloud 4.0.8

owncloud owncloud 4.0.7

owncloud owncloud 4.0.15

owncloud owncloud 4.0.14

owncloud owncloud 3.0.2

owncloud owncloud 3.0.1

owncloud owncloud 4.5.9

owncloud owncloud 4.5.8

owncloud owncloud 4.5.12

owncloud owncloud 4.5.11

owncloud owncloud 4.0.6

owncloud owncloud 4.0.5

owncloud owncloud 4.0.13

owncloud owncloud 4.0.12

owncloud owncloud 4.0.11

owncloud owncloud 3.0.0

Exploits

Vulnerability title: Remote Code Execution in ownCloud CVE: CVE-2014-2044 Vendor: ownCloud Product: ownCloud Affected version: 40x & 45x Fixed version: 50 Reported by: Alejo Murillo Moya Details: A remote code execution has been found and confirmed within ownCloud as an authenticated user A successful attack could allow an authenticated ...
ownCloud versions 40x and 45x suffer from a remote code execution vulnerability ...