CVE-2014-2044: Code Injection
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2044?
CVE-2014-2044 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2014-2044?
To fix CVE-2014-2044, upgrade to ownCloud version 5.0 or later, which addresses the vulnerability.
Which versions are affected by CVE-2014-2044?
CVE-2014-2044 affects ownCloud versions prior to 5.0, particularly on Windows platforms.
What type of vulnerability is CVE-2014-2044?
CVE-2014-2044 is categorized as an incomplete blacklist vulnerability allowing unauthorized file uploads and code execution.
Can CVE-2014-2044 be exploited by remote users?
Yes, CVE-2014-2044 can be exploited by remote authenticated users to bypass access controls.