| Vulnerability Name: | CVE-2015-4716 (CCN-108556) | ||||||||||||||||
| Assigned: | 2015-06-24 | ||||||||||||||||
| Published: | 2015-06-24 | ||||||||||||||||
| Updated: | 2016-12-07 | ||||||||||||||||
| Summary: | Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors. | ||||||||||||||||
| CVSS v3 Severity: | 6.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L) 5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||
| Vulnerability Type: | CWE-22 | ||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2015-4716 Source: DEBIAN Type: UNKNOWN DSA-3373 Source: BID Type: UNKNOWN 76159 Source: XF Type: UNKNOWN owncloud-cve20154716-file-include(108556) Source: CCN Type: ownCloud Security Advisory oC-SA-2015-006 Local file inclusion on MS Windows Platform (oC-SA-2015-006) Source: CONFIRM Type: Vendor Advisory https://owncloud.org/security/advisory/?id=oc-sa-2015-006 | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||