CVE-2015-4717

EUVD-2015-4734
The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
owncloudowncloud
𝑥
≤ 6.0.7
owncloudowncloud_server
7.0.0
owncloudowncloud_server
7.0.1
owncloudowncloud_server
7.0.2
owncloudowncloud_server
7.0.3
owncloudowncloud_server
7.0.4
owncloudowncloud_server
7.0.5
owncloudowncloud_server
8.0.0
owncloudowncloud_server
8.0.2
owncloudowncloud_server
8.0.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
owncloud
precise
not-affected
trusty
dne
vivid
dne
wily
dne
Common Weakness Enumeration