CVE-2014-2044

EUVD-2014-2096
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
Affected Products (NVD)
VendorProductVersion
owncloudowncloud
𝑥
≤ 4.5.13
owncloudowncloud_server
3.0.0
owncloudowncloud_server
3.0.1
owncloudowncloud_server
3.0.2
owncloudowncloud_server
3.0.3
owncloudowncloud_server
4.0.0
owncloudowncloud_server
4.0.1
owncloudowncloud_server
4.0.2
owncloudowncloud_server
4.0.3
owncloudowncloud_server
4.0.4
owncloudowncloud_server
4.0.5
owncloudowncloud_server
4.0.6
owncloudowncloud_server
4.0.7
owncloudowncloud_server
4.0.8
owncloudowncloud_server
4.0.9
owncloudowncloud_server
4.0.10
owncloudowncloud_server
4.0.11
owncloudowncloud_server
4.0.12
owncloudowncloud_server
4.0.13
owncloudowncloud_server
4.0.14
owncloudowncloud_server
4.0.15
owncloudowncloud_server
4.0.16
owncloudowncloud_server
4.5.0
owncloudowncloud_server
4.5.1
owncloudowncloud_server
4.5.2
owncloudowncloud_server
4.5.3
owncloudowncloud_server
4.5.4
owncloudowncloud_server
4.5.5
owncloudowncloud_server
4.5.6
owncloudowncloud_server
4.5.7
owncloudowncloud_server
4.5.8
owncloudowncloud_server
4.5.9
owncloudowncloud_server
4.5.10
owncloudowncloud_server
4.5.11
owncloudowncloud_server
4.5.12
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud
lucid
dne
precise
not-affected
quantal
not-affected
saucy
not-affected