Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-4715

Опубликовано: 17 фев. 2020
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:*:*:*
Версия до 6.0.8 (исключая)
cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*
Версия от 7.0.0 (включая) до 7.0.6 (исключая)
cpe:2.3:a:owncloud:owncloud_server:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.0.4 (исключая)

EPSS

Процентиль: 80%
0.01359
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 4.9
ubuntu
почти 6 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

CVSS3: 4.9
debian
почти 6 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownClo ...

CVSS3: 4.9
github
больше 3 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

EPSS

Процентиль: 80%
0.01359
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-552