CVE-2014-1665
MEDIUMowncloud < 6.0.1 - Authenticated Stored Cross-Site Scripting via Uploaded Filename
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-1665. PoCs published by absane.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in ownCloud 6.0.0a, where a malicious filename triggers JavaScript execution when viewed or deleted. The PoC also bypasses CSRF protection to enable external storage and mount the server's root filesystem, potentially leading to unauthorized access.
Description
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the filename of an uploaded file.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in ownCloud 6.0.0a, where a malicious filename triggers JavaScript execution when viewed or deleted. The PoC also bypasses CSRF protection to enable external storage and mount the server's root filesystem, potentially leading to unauthorized access.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N