7.8
CVSSv2

CVE-2015-4717

Published: 21/10/2015 Updated: 22/10/2015
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The filename sanitization component in ownCloud Server prior to 6.0.8, 7.0.x prior to 7.0.6, and 8.0.x prior to 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote malicious users to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.

Vulnerable Product Search on Vulmon Subscribe to Product

owncloud owncloud 7.0.1

owncloud owncloud 7.0.3

owncloud owncloud 7.0.5

owncloud owncloud 8.0.0

owncloud owncloud 8.0.2

owncloud owncloud 8.0.3

owncloud owncloud 7.0.2

owncloud owncloud 7.0.4

owncloud owncloud

owncloud owncloud 7.0.0

Vendor Advisories

Multiple vulnerabilities were discovered in ownCloud, a cloud storage web service for files, music, contacts, calendars and many more These flaws may lead to the execution of arbitrary code, authorization bypass, information disclosure, cross-site scripting or denial of service For the stable distribution (jessie), these problems have been fixed ...