CVE-2013-2089

EUVD-2013-2064
Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the file in /data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Affected Products (NVD)
VendorProductVersion
owncloudowncloud
𝑥
≤ 5.0.5
owncloudowncloud_server
5.0.0
owncloudowncloud_server
5.0.1
owncloudowncloud_server
5.0.2
owncloudowncloud_server
5.0.3
owncloudowncloud_server
5.0.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud
lucid
dne
precise
not-affected
quantal
not-affected
raring
ignored
saucy
not-affected
trusty
dne