Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2014-10-06T23:00:00
Updated: 2024-08-06T09:58:16.206Z
Reserved: 2014-02-19T00:00:00
Link: CVE-2014-2044
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-10-06T23:55:08.327
Modified: 2024-11-21T02:05:31.460
Link: CVE-2014-2044
Redhat
No data.