vendor:
ownCloud
by:
Alejo Murillo Moya
7,5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: ownCloud
Affected Version From: 4.0.x
Affected Version To: 4.5.x
Patch Exists: YES
Related CWE: CVE-2014-2044
CPE: a:owncloud:owncloud
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2014
Remote Code Execution in ownCloud
A remote code execution has been found and confirmed within ownCloud as an authenticated user. A successful attack could allow an authenticated attacker to execute PHP code, which could lead to a full compromise of the server and associated infrastructure. Please note that only the Windows versions of ownCloud are affected and that valid credentials are required. It is possible to create a custom .htaccess into the user's folder on Windows version of the application, which will enable PHP execution on the folder. This vulnerability exists because it is possible to bypass the internal blacklists using Windows ADS (Alternate Data Streams).
Mitigation:
Upgrade to ownCloud 5.0 or later.