First published: Wed Jun 04 2014(Updated: )
settings/personal.php in ownCloud 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via crafted mount point settings.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ownCloud | =4.5.0 | |
ownCloud | =4.5.1 | |
ownCloud | =4.5.2 | |
ownCloud | =4.5.3 | |
ownCloud | =4.5.4 | |
ownCloud | =4.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0204 has a high severity rating due to the potential for remote authenticated users to execute arbitrary PHP code.
To fix CVE-2013-0204, upgrade ownCloud to version 4.5.6 or later where the vulnerability is patched.
CVE-2013-0204 affects ownCloud versions 4.5.0 to 4.5.5.
CVE-2013-0204 allows remote authenticated users to execute arbitrary PHP code through crafted mount point settings.
Yes, exploitation of CVE-2013-0204 requires authentication as a remote user on the ownCloud platform.