Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-2044

Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.139
EPSS Ranking 93.9%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2014-2044


Contact Us

Shodan ® - All rights reserved