ownCloud 'fileuploaded.php' Arbitrary File Upload Vulnerability
BID:55223
Info
ownCloud 'fileuploaded.php' Arbitrary File Upload Vulnerability
| Bugtraq ID: | 55223 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2012 12:00AM |
| Updated: | Aug 27 2012 12:00AM |
| Credit: | Julien Cayssol |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
ownCloud 'fileuploaded.php' Arbitrary File Upload Vulnerability
ownCloud is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this issue to upload arbitrary code and execute it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
ownCloud 4.0.6 is vulnerable; other versions may also be affected.
ownCloud is prone to a vulnerability that lets attackers upload arbitrary files. The issue occurs because the application fails to adequately sanitize user-supplied input.
An attacker can exploit this issue to upload arbitrary code and execute it in the context of the web server process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.
ownCloud 4.0.6 is vulnerable; other versions may also be affected.
Exploit / POC
ownCloud 'fileuploaded.php' Arbitrary File Upload Vulnerability
An attacker can exploit the issue using a browser.
An attacker can exploit the issue using a browser.
Solution / Fix
ownCloud 'fileuploaded.php' Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
ownCloud 'fileuploaded.php' Arbitrary File Upload Vulnerability
References:
References:
- Changelogs (owncloud)
- ownCloud Homepage (ownCloud)