Логотип exploitDog
bind:CVE-2014-2044
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-2044

Количество 4

Количество 4

ubuntu логотип

CVE-2014-2044

больше 11 лет назад

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2014-2044

больше 11 лет назад

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2014-2044

больше 11 лет назад

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud befo ...

CVSS2: 7.5
EPSS: Средний
github логотип

GHSA-3mmx-4r9c-p6f8

больше 3 лет назад

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-2044

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

CVSS2: 7.5
18%
Средний
больше 11 лет назад
nvd логотип
CVE-2014-2044

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

CVSS2: 7.5
18%
Средний
больше 11 лет назад
debian логотип
CVE-2014-2044

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud befo ...

CVSS2: 7.5
18%
Средний
больше 11 лет назад
github логотип
GHSA-3mmx-4r9c-p6f8

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

18%
Средний
больше 3 лет назад

Уязвимостей на страницу