CVE-2013-2089

Description

Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the file in /data.

Risk Information

Base Score
5.0
MODERATE
Vector
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.391

Associated Vulnerability

VulnerabilityOS Platform
update owncloud 5.0.5 to latest versionWindows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-339158ownCloud (5.3.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234