ownCloud 'lib/migrate.php' Local File Disclosure Vulnerability
BID:58483
Info
ownCloud 'lib/migrate.php' Local File Disclosure Vulnerability
| Bugtraq ID: | 58483 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-1851 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 11 2013 12:00AM |
| Updated: | Mar 11 2013 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
ownCloud ownCloud 4.5.7 ownCloud ownCloud 4.5.2 ownCloud ownCloud 4.5 ownCloud ownCloud 4.0.12 ownCloud ownCloud 4.0.9 ownCloud ownCloud 4.0.7 ownCloud ownCloud 4.0.6 ownCloud ownCloud 4.0.5 ownCloud ownCloud 4.0.4 ownCloud ownCloud 4.5.6 ownCloud ownCloud 4.5.5 ownCloud ownCloud 4.0.3 ownCloud ownCloud 4.0.2 ownCloud ownCloud 4.0.11 ownCloud ownCloud 4.0.10 ownCloud ownCloud 4.0.1 |
| Not Vulnerable: |
ownCloud ownCloud 4.5.8 ownCloud ownCloud 4.0.13 |
Discussion
ownCloud 'lib/migrate.php' Local File Disclosure Vulnerability
ownCloud is prone to a local file-disclosure vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to obtain sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
ownCloud versions prior to 4.5.8 and 4.0.13 are vulnerable.
ownCloud is prone to a local file-disclosure vulnerability because it fails to sanitize user-supplied input.
An attacker may leverage this issue to obtain sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
ownCloud versions prior to 4.5.8 and 4.0.13 are vulnerable.
Exploit / POC
ownCloud 'lib/migrate.php' Local File Disclosure Vulnerability
Attackers can exploit this issue using a browser.
Attackers can exploit this issue using a browser.
Solution / Fix
ownCloud 'lib/migrate.php' Local File Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ownCloud 'lib/migrate.php' Local File Disclosure Vulnerability
References:
References:
- ownCloud Homepage (ownCloud)
- ownCloud Security Advisories (2013-008, 2013-009, 2013-010) (SECLISTS)
- user_migrate: Local file disclosure (oC-SA-2013-010) (ownCloud)