CVE-2013-2089

Published Mar 14, 2014

Last updated 11 years ago

Overview

Description
Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the file in /data.
Source
secalert@redhat.com
NVD status
Analyzed

Risk scores

CVSS 2.0

Type
Primary
Base score
4.6
Impact score
6.4
Exploitability score
3.9
Vector string
AV:N/AC:H/Au:S/C:P/I:P/A:P

Weaknesses

nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Evaluator

Comment
Per: https://cwe.mitre.org/data/definitions/184.html "CWE-184: Incomplete Blacklist"
Impact
-
Solution
-

Configurations