7.8

CVE-2015-4717

The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Owncloud ≫ Owncloud Version <= 6.0.7
Owncloud ≫ Owncloud Server Version 7.0.0
Owncloud ≫ Owncloud Server Version 7.0.1
Owncloud ≫ Owncloud Server Version 7.0.2
Owncloud ≫ Owncloud Server Version 7.0.3
Owncloud ≫ Owncloud Server Version 7.0.4
Owncloud ≫ Owncloud Server Version 7.0.5
Owncloud ≫ Owncloud Server Version 8.0.0
Owncloud ≫ Owncloud Server Version 8.0.2
Owncloud ≫ Owncloud Server Version 8.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.83% 0.848
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.debian.org/security/2015/dsa-3373
http://www.securityfocus.com/bid/76161
https://owncloud.org/security/advisory/?id=oc-sa-2015-007
Vendor Advisory