7.8

CVE-2015-4717

The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.

Data is provided by the National Vulnerability Database (NVD)
OwncloudOwncloud Version <= 6.0.7
OwncloudOwncloud Server Version7.0.0
OwncloudOwncloud Server Version7.0.1
OwncloudOwncloud Server Version7.0.2
OwncloudOwncloud Server Version7.0.3
OwncloudOwncloud Server Version7.0.4
OwncloudOwncloud Server Version7.0.5
OwncloudOwncloud Server Version8.0.0
OwncloudOwncloud Server Version8.0.2
OwncloudOwncloud Server Version8.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.69% 0.709
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C