VulnerabilityModified
CVE-2014-4929
Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include and execute arbitrary local files via a ..
MEDIUM 6.8EPSS 2.34%
Does this matter?
Lower severity and a low EPSS score (2.34%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a filename, related to index.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.34% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- owncloud/owncloud server · owncloud/owncloud
- Source
- cve@mitre.org
References
- http://advisories.mageia.org/MGASA-2014-0301.html
- http://owncloud.org/security/advisory/?id=oc-sa-2014-018Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:140
- http://www.securityfocus.com/bid/68975
- http://advisories.mageia.org/MGASA-2014-0301.html
- http://owncloud.org/security/advisory/?id=oc-sa-2014-018Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:140
- http://www.securityfocus.com/bid/68975
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.