Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-82h9-wxqp-j6pq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

EPSS

Процентиль: 80%
0.01359
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 6 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

CVSS3: 4.9
nvd
почти 6 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

CVSS3: 4.9
debian
почти 6 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownClo ...

EPSS

Процентиль: 80%
0.01359
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-552