Description
icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the (1) listShares function in Server.php or the (2) connect or (3) read function in Share.php.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://owncloud.org/security/advisory/?id=oc-sa-2015-017
Vendor Advisory x_refsource_confirm
https://github.com/icewind1991/SMB/commit/33ab10cc4d5c3e48cba3a074b5f9fc67590cd032
Scores
EPSS
0.0091
EPSS Percentile
76.1%
Details
CWE
CWE-78
Status
published
Products (2)
owncloud/owncloud
< 8.1.1
owncloud/smb
< 1.0.2
Published
Oct 21, 2015
Tracked Since
Feb 18, 2026