CVE-2014-2044

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
owncloudowncloud
𝑥
≤ 4.5.13
owncloudowncloud_server
3.0.0
owncloudowncloud_server
3.0.1
owncloudowncloud_server
3.0.2
owncloudowncloud_server
3.0.3
owncloudowncloud_server
4.0.0
owncloudowncloud_server
4.0.1
owncloudowncloud_server
4.0.2
owncloudowncloud_server
4.0.3
owncloudowncloud_server
4.0.4
owncloudowncloud_server
4.0.5
owncloudowncloud_server
4.0.6
owncloudowncloud_server
4.0.7
owncloudowncloud_server
4.0.8
owncloudowncloud_server
4.0.9
owncloudowncloud_server
4.0.10
owncloudowncloud_server
4.0.11
owncloudowncloud_server
4.0.12
owncloudowncloud_server
4.0.13
owncloudowncloud_server
4.0.14
owncloudowncloud_server
4.0.15
owncloudowncloud_server
4.0.16
owncloudowncloud_server
4.5.0
owncloudowncloud_server
4.5.1
owncloudowncloud_server
4.5.2
owncloudowncloud_server
4.5.3
owncloudowncloud_server
4.5.4
owncloudowncloud_server
4.5.5
owncloudowncloud_server
4.5.6
owncloudowncloud_server
4.5.7
owncloudowncloud_server
4.5.8
owncloudowncloud_server
4.5.9
owncloudowncloud_server
4.5.10
owncloudowncloud_server
4.5.11
owncloudowncloud_server
4.5.12
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud
lucid
dne
precise
not-affected
quantal
not-affected
saucy
not-affected