CVE-2013-1851

Published Mar 14, 2014

Last updated 11 years ago

Overview

Description
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.13 and 4.5.x before 4.5.8, when the user_migrate application is enabled, allows remote authenticated users to import arbitrary files to the user's account via unspecified vectors.
Source
secalert@redhat.com
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
3.5
Impact score
2.9
Exploitability score
6.8
Vector string
AV:N/AC:M/Au:S/C:N/I:P/A:N

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Evaluator

Comment
Per: https://cwe.mitre.org/data/definitions/184.html "CWE-184: Incomplete Blacklist"
Impact
-
Solution
-

Configurations