CVE-2013-1939
Published Mar 14, 2014
Last updated a year ago
Overview
- Description
- The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ (backslash) character.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-20
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:fruux:sabredav:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7E6CC4D0-A201-42E5-AC5E-617179FA441E", "versionEndExcluding": "1.6.9", "versionStartIncluding": "1.6.0" }, { "criteria": "cpe:2.3:a:fruux:sabredav:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C11FC69F-A24F-45A0-B78E-D7831E20E8B9", "versionEndExcluding": "1.7.7", "versionStartIncluding": "1.7.0" }, { "criteria": "cpe:2.3:a:fruux:sabredav:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0B9AFA14-DF70-48AE-A5F4-F75668D01C55", "versionEndExcluding": "1.8.5", "versionStartIncluding": "1.8.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "80869418-F6A2-4D8B-BC2A-AA648BB84FF8", "versionEndExcluding": "4.0.14", "versionStartIncluding": "4.0.0" }, { "criteria": "cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E831542E-2D13-4C84-A94A-0EB8DADD77A1", "versionEndExcluding": "4.5.9", "versionStartIncluding": "4.5.0" }, { "criteria": "cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EEB4A18C-5F51-4B3A-8DD9-E11BA580F614", "versionEndExcluding": "5.0.4", "versionStartIncluding": "5.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256" } ], "operator": "OR" } ], "operator": "AND" } ]