CVE-2012-5610

owncloud < 4.0.9 and 4.5.x < 4.5.2 - Authenticated Remote Code Execution via Crafted Filename

Title source: llm
STIX 2.1

Description

Incomplete blacklist vulnerability in lib/filesystem.php in ownCloud before 4.0.9 and 4.5.x before 4.5.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a special crafted name.

References (8)

Core 8

Scores

EPSS 0.0109
EPSS Percentile 78.2%

Details

CWE
CWE-20
Status published
Products (13)
owncloud/owncloud < 4.0.8
owncloud/owncloud_server 3.0.0
owncloud/owncloud_server 3.0.1
owncloud/owncloud_server 3.0.2
owncloud/owncloud_server 3.0.3
owncloud/owncloud_server 4.0.0
owncloud/owncloud_server 4.0.1
owncloud/owncloud_server 4.0.2
owncloud/owncloud_server 4.0.3
owncloud/owncloud_server 4.0.4
... and 3 more
Published Dec 18, 2012
Tracked Since Feb 18, 2026