CVE-2014-4929

ownCloud Server <6.0.4 - Path Traversal

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a filename, related to index.php.

References (4)

Core 4
Core References
Third Party Advisory x_refsource_confirm
http://advisories.mageia.org/MGASA-2014-0301.html
Vendor Advisory x_refsource_confirm
http://owncloud.org/security/advisory/?id=oc-sa-2014-018
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2014:140
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68975

Scores

EPSS 0.0059
EPSS Percentile 69.4%

Details

CWE
CWE-22
Status published
Products (21)
owncloud/owncloud < 5.0.16
owncloud/owncloud_server 6.0.0
owncloud/owncloud_server 6.0.1
owncloud/owncloud_server 6.0.2
owncloud/owncloud_server 6.0.3
owncloud/owncloud_server 5.0.0
owncloud/owncloud_server 5.0.1
owncloud/owncloud_server 5.0.2
owncloud/owncloud_server 5.0.3
owncloud/owncloud_server 5.0.4
... and 11 more
Published Aug 20, 2014
Tracked Since Feb 18, 2026