CVE-2014-2044
Summary
| CVE | CVE-2014-2044 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-06 23:55:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Owncloud | Owncloud | All | All | All | All |
| Application | Owncloud | Owncloud Server | 3.0.0 | All | All | All |
| Application | Owncloud | Owncloud Server | 3.0.1 | All | All | All |
| Application | Owncloud | Owncloud Server | 3.0.2 | All | All | All |
| Application | Owncloud | Owncloud Server | 3.0.3 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.0 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.1 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.10 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.11 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.12 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.13 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.14 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.15 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.16 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.2 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.3 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.4 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.5 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.6 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.7 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.8 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.0.9 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.0 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.1 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.10 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.11 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.12 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.2 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.3 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.4 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.5 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.6 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.7 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.8 | All | All | All |
| Application | Owncloud | Owncloud Server | 4.5.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| ownCloud 4.0.x, 4.5.x (upload.php, filename param) - Remote Code Execution | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit |
| Security Advisory SA57267 - ownCloud Windows ADS File Upload Security Bypass Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Full Disclosure: CVE-2014-2044 - Remote Code Execution in ownCloud | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| ownCloud 'filename' Parameter Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/104082 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE-2014-2044 - Portcullis | af854a3a-2127-422b-91ae-364da2661108 | www.portcullis-security.com | Exploit |
| ownCloud 4.0.x / 4.5.x Remote Code Execution ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.