Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-4715

Опубликовано: 17 фев. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4
CVSS3: 4.9

Описание

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

esm-apps/xenial

not-affected

1.0.0-4
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
precise

DNE

precise/esm

DNE

trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 80%
0.01359
Низкий

4 Medium

CVSS2

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
nvd
почти 6 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

CVSS3: 4.9
debian
почти 6 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownClo ...

CVSS3: 4.9
github
больше 3 лет назад

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been mounted, allows remote administrators of Dropbox.com to read arbitrary files via an @ (at sign) character in unspecified POST values.

EPSS

Процентиль: 80%
0.01359
Низкий

4 Medium

CVSS2

4.9 Medium

CVSS3