Security Advisory

CVE-2014-2044

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-10-06 23:00:00
Last updated 2024-08-06 09:58:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.